Privacy Policy
Last updated: June 2026
This Privacy Policy of ZeroQuarry Pty Ltd (us, we, our) sets out how we treat the Personal Information that we collect, use and disclose and our procedures regarding the handling of Personal Information, including the collection, use, disclosure and storage of information, as well as the right of individuals to access and correct that information. We operate the platform called 'ZeroQuarry', which includes the website with domain name zeroquarry.com (Platform).
From time to time, we may revise or update this Privacy Policy or our information handling practices. If we do so, the revised Privacy Policy will be published on the Platform at zeroquarry.com/privacy
We may collect Personal Information in order to conduct our business, to provide and market our services and to meet our legal obligations. By using the Platform or our services, or by providing any Personal Information to us, you consent to the collection, use and disclosure of your Personal Information as set out in this Privacy Policy.
The types of information
The Privacy Act 1988 (Cth) (Privacy Act) defines types of information, including Personal Information and Sensitive Information.
Personal Information
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable:
- whether the information or opinion is true or not; and
- whether the information or opinion is recorded in a material form or not.
If the information does not disclose your identity or enable your identity to be ascertained, it will in most cases not be classified as 'Personal Information' and will not be subject to this Privacy Policy.
Sensitive Information
Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
Sensitive Information will be used by Us only:
- for the primary purpose for which it was obtained;
- for a secondary purpose that is directly related to the primary purpose; and
- with your explicit consent or where its collection, use or disclosure is required or authorised by law.
The types of Personal Information and Sensitive Information we collect and hold
The types of Personal Information we may collect and hold includes (but is not limited to) personal information about:
- your contact details, such as name, email address, phone number and postal address;
- your enquiry and membership information;
- your marketing preferences and communications history;
- other personal information required to provide our services in specific cases;
- technical and usage data, such as IP address, browser type, device information and cookies/analytics data; and
- details of your use of our products or services.
You are not obliged to provide Personal Information to us. However, in many cases, if you do not provide us with the necessary information, we may not be able to supply the relevant functionality of the Platform or our services effectively.
In some circumstances, you may provide to us, and we may collect from you, Personal Information about a third party. Where you provide the Personal Information of a third party, you must ensure that the third party is aware of this Privacy Policy, understands it and agrees to accept it.
The Platform is intended for adults aged 18 years or over.
If it is necessary to provide specific services to you, we may collect Sensitive Information about you. However, we will only collect Sensitive Information from you if you agree to provide it to us, you authorise us to obtain it from a third party or where the collection of the information is required or authorised by or under an Australian law or a court/tribunal order or otherwise where the collection is not prohibited under Australian law.
How Personal Information and Sensitive Information is collected and held by us
We collect Personal Information and Sensitive Information in the following ways:
- when you fill in and submit to us an online form or any other form;
- when you submit Personal Information or Sensitive Information through the Platform (such as when you send us a message) or provide it to us in any other way;
- in person, for example, when you engage with our employees, contractors, facilitators, agents, or customer service representatives; and
- in the course of providing services to you.
Collection of Personal Information through activity
Information that may identify you as a user may be gathered during your access to the Platform.
The Platform may include pages that use 'cookies'. A cookie is a unique identification number that allows the server to identify and interact more effectively with your computer or device. The cookie assists us in identifying what our users find interesting on the Platform.
With your consent, our marketing website uses Google Analytics to measure traffic and advertising performance, and PostHog to understand visits, navigation, conversion events and the journey from the website into the ZeroQuarry product. Where the same browser proceeds to our product, PostHog may associate the earlier anonymous website activity with the account after sign-in. You may decline analytics from the cookie notice, in which case these analytics tools are not loaded on the marketing website.
A cookie may be allocated each time you use the Platform. The cookie does not identify you as an individual in our data collection process; however, it does identify your internet service provider.
You can configure your access to the Platform to refuse cookies. If you do so, you may not be able to use all or part of the Platform.
Artificial Intelligence (AI) tools
The Platform uses AI-assisted systems to analyse customer-authorised assets/application data and generate security findings, reports, summaries and remediation recommendations.
AI-generated outputs are produced using probabilistic models and may not always be accurate, complete or appropriate for your intended use. These AI-generated outputs assist customers in their decision-making but do not determine or make decisions on behalf of customers or individuals.
The Platform does not use Personal Information to make decisions based solely on automated processing that have legal effects, or similarly significant effects, on individuals. Any decisions made using AI-generated outputs remain subject to review and approval by the customer or other authorised users.
Unless expressly stated otherwise, AI-generated outputs are not routinely reviewed by us before they are provided to you. You are responsible for reviewing and validating all AI-generated outputs before relying on them for operational, security, compliance, disclosure or remediation purposes.
Where human review of AI-generated outputs is provided, we will describe the circumstances in which such review occurs and the persons or roles responsible for conducting it.
Where consent is required, we obtain it separately through a clear affirmative action. You may withdraw your consent at any time, subject to our ability to continue providing services.
The purposes for which we collect, hold, use and disclose Personal Information and Sensitive Information
We collect, hold, use and disclose Personal Information or Sensitive Information for a variety of business purposes including:
- to provide the products or services you have requested from us;
- to improve our business, products and services;
- to promote our business to you;
- to market our other services or products to you;
- to handle and respond to your enquiries, complaints or concerns; and
- to provide Personal Information or Sensitive Information to third parties as set out in this Privacy Policy, only where necessary, with appropriate safeguards and your consent where required by law.
We use your information only for the purpose for which it was collected, or a related purpose you would reasonably expect. Otherwise, we will ask for consent or rely on another APP exception.
Direct marketing
We also collect, hold, use and disclose your Personal Information to:
- notify you about the details of new services and products offered by us;
- send you our newsletters and other marketing publications;
- administer our databases for client service, marketing and financial accounting purposes; and
- to comply with our legal requirements regarding the collection and retention of information concerning the products and services that we provide.
All marketing emails and SMS messages include an unsubscribe facility. By using the Platform, you consent to the receipt of direct marketing material. If you do not wish to disclose your Personal Information for the purpose of direct marketing or you would like to opt-out of receiving direct marketing communications, you can do so by contacting us using the contact details set out below, or by following the instructions to unsubscribe which are contained in a communication that you receive from us.
We may use your Personal Information (but never Sensitive Information) to contact you about our services, updates, and promotions.
Third Party Service Providers
We may disclose your Personal Information to third parties who work with us in our business to promote, market or improve the services that we provide, including:
- providers of customer relations management database services and marketing database services;
- marketing consultants, promotion companies and website hosts;
- partnered businesses;
- linked service providers; and
- consultants and professional advisers.
We use third-party payment service providers to process transactions securely. These providers may collect and store your payment details in accordance with their own privacy policies.
We may also combine your Personal Information with information available from other sources, including the entities mentioned above, to help us provide better services to you.
Where we do share information with third parties, we require that there are contracts in place that only allow use and disclosure of Personal Information to provide the service and that protect your Personal Information in accordance with Australian law. Otherwise, we will disclose Personal Information to others if you have given us permission, or if the disclosure relates to the main purpose for which we collected the information, and you would reasonably expect us to do so.
How we store, hold, and protect your Personal Information and Sensitive Information
We store Personal Information and Sensitive Information using secure electronic storage systems and, where applicable, paper-based records. The Platform is currently primarily hosted in the United States, where Personal Information is generally stored, including in backup and disaster recovery systems. Depending on the services you use, your deployment configuration, and any customer-selected or customer-hosted AI or large language model (LLM) providers, Personal Information may also be stored or processed in other countries where our service providers or infrastructure operate.
We implement reasonable technical and organisational measures in accordance with APP 11 to protect Personal Information from misuse, interference and loss, and from unauthorised access, modification or disclosure, including encryption, access controls, multi-factor authentication, network security monitoring, incident response procedures, vendor oversight, staff training and data minimisation practices.
We take reasonable steps to protect your Personal Information and Sensitive Information against loss, unauthorised access, use modification or disclosure. Some examples of the steps we take to protect your Personal Information and Sensitive Information include:
- ensuring there are suitable password protection measures and access privileges in place to monitor and control access to our IT systems;
- imposing restrictions on physical access to paper files;
- requiring any third parties engaged by us to provide appropriate assurances to handle your Personal Information and Sensitive Information in a manner consistent with Australian law; and
- taking reasonable steps to destroy or de-identify Personal Information and Sensitive Information after we no longer need it for our business or to comply with the law.
We store, process, and retain your information only for as long as we need it for the purposes described in this Privacy Policy. When we no longer need your information, we take reasonable steps to destroy or de-identify it, unless we are required or authorised by law to retain your information for a longer period.
We retain Personal Information for the periods required by applicable law.
The Australian Privacy Principles (APP):
- permit you to obtain access to the Personal Information or Sensitive Information we hold about you in certain circumstances (APP 12); and
- allow you to correct inaccurate Personal Information or Sensitive Information subject to certain exceptions (APP 13).
Where you would like to obtain such access, please contact Us in writing on the contact details set out at the bottom of this Privacy Policy.
Data Breach Response
We maintain a written data breach response plan that complies with the Privacy Act. Where we have reasonable grounds to suspect that an eligible data breach may have occurred, we will promptly contain and investigate the incident, take reasonable steps to mitigate harm and preserve evidence, and carry out an assessment in a reasonable and expeditious manner and, where required by law, within 30 days.
If we become aware of reasonable grounds to believe an eligible data breach has occurred, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, in line with the Privacy Act. If direct notification is not practicable, we will publish a notification. We will keep records of the incident, our assessment, and our response, and take reasonable steps to prevent a recurrence.
Cross-border disclosure
We store and process Personal Information in Australia, the United States and, where applicable, other countries in which our related bodies corporate, service providers, contractors, hosting providers or customer-selected AI or LLM providers operate.
Before disclosing Personal Information to an overseas recipient, we will comply with APP 8 by taking reasonable steps in the circumstances to ensure the recipient does not breach the APPs in relation to the information, unless an exception under APP 8.2 applies, including where you have provided informed consent to the disclosure or the disclosure is required or authorised by law.
Where we rely on your consent to an overseas disclosure, you acknowledge and agree that APP 8.1 will not apply and that we will not be accountable under section 16C of the Privacy Act for the overseas recipient's handling of the Personal Information.
General Data Protection Regulation (GDPR) for the European Union (EU)
Your Personal Information may be transferred to recipients in the EU. EU member countries have data protection laws, including the GDPR, which generally provide a high standard of protection for Personal Information that is substantially similar to the APP. You will also have mechanisms available to enforce protection of your Personal Information under the GDPR. In the circumstances, we do not require the overseas recipients to comply with the APP and we will not be liable for a breach of the APP if your Personal Information is mishandled. Where we rely on your consent to an overseas disclosure, you acknowledge and agree that APP 8.1 will not apply and that we will not be accountable under section 16C of the Privacy Act for the overseas recipient's handling of the Personal Information.
- We will comply with the principles of data protection set out in the GDPR for the purpose of fairness, transparency and lawful data collection and use.
- For the purposes of the GDPR, we may act as either a controller or processor of Personal Information depending on the circumstances in which the information is collected and processed.
- We must establish a lawful basis for processing your Personal Information. The legal basis for which we collect your personal information depends on the data that we collect and how we use it.
- Where required by the GDPR, we will obtain your consent before processing your Personal Information. We will keep your data safe and secure.
- We will also process your Personal Information if it is necessary for our legitimate interests, or to fulfil a contractual or legal obligation.
- We process your Personal Information if it is necessary to protect your life or in a medical situation, it is necessary to carry out a public function, a task of public interest or if the function has a clear basis in law.
- We do not intentionally collect special categories of Personal Information or personal data (as defined in Article 9 GDPR) unless this is necessary for a lawful purpose and one of the conditions in Article 9 GDPR applies, including where explicit consent has been obtained.
- If you are under the age at which you can lawfully provide consent under applicable GDPR requirements in your country, you must obtain consent from a parent or legal guardian before providing us with Personal Information. We do not knowingly collect or process the Personal Information of children.
Your rights under the GDPR
- If you are an individual residing in the EU, you have certain rights as to how your Personal Information is obtained and used. We will comply with your rights under the GDPR as to how your Personal Information is used and controlled if you are an individual residing in the EU.
- Except as otherwise provided in the GDPR, you have the following rights:
- to be informed how your Personal Information is being used;
- access your Personal Information (in most cases, we will provide a copy free of charge, although a reasonable fee may be charged where permitted under the GDPR);
- to correct your Personal Information if it is inaccurate or incomplete;
- to delete your Personal Information (also known as 'the right to be forgotten');
- to restrict processing of your Personal Information;
- to lodge a complaint with a supervisory authority;
- to retain and reuse your Personal Information for your own purposes;
- to object to your Personal Information being used; and
- to object against automated decision making and profiling.
- Please contact us at any time to exercise your rights under the GDPR at the contact details in this Privacy Policy.
- We may ask you to verify your identity before acting on any of your requests.
Hosting and international data transfers
Personal Information that we collect may from time to time be transferred to, stored, processed or accessed in countries outside Australia, including countries such as the United States in which our related bodies corporate, service providers, contractors, business partners or hosting providers or customer-selected third-party AI or large language model (LLM) providers operate. The countries in which Personal Information is processed may vary depending on the services you use and any AI models or processing locations selected or configured by you.
These countries may include:
- those where our group companies or we have offices or facilities. Transfers to these countries will be protected by appropriate safeguards. These safeguards may include standard data protection clauses adopted or approved by the European Commission, which are available from the European Commission website, or binding corporate rules, a copy of which can be obtained from our privacy officer;
- countries where our website hosting facilities are located. Transfers to these countries are protected by appropriate safeguards, including standard data protection clauses adopted or approved by the European Commission (available from the European Commission website) or binding corporate rules (a copy of which can be obtained from our privacy officer); and
- countries where our suppliers and contractors are located. Transfers to these countries are protected by appropriate safeguards, including standard data protection clauses adopted or approved by the European Commission (available from the European Commission website) or binding corporate rules (a copy of which can be obtained from our privacy officer).
You acknowledge that personal data or Personal Information that you submit for publication through our website or services may be available, via the internet, around the world. We cannot prevent others from using (or misusing) such personal data or Personal Information.
How we handle requests to access your Personal Information or Sensitive Information
You may request access to your Personal Information or Sensitive Information under the Privacy Act, or request deletion of your Personal Information or Sensitive Information in accordance with our data retention policies. You can make such a request by contacting us using the contact details set out in this Privacy Policy.
We will respond to any such request for access as soon as reasonably practicable. Where access is to be given, we will provide you with a copy or details of your Personal Information and Sensitive Information in the manner requested by you where it is reasonable and practicable to do so.
We will not charge you a fee for making a request to access your Personal Information and Sensitive Information. However, we may charge you a reasonable fee for giving you access to your information.
We may refuse access to your requested information, or provide only partial access, where required by law, including where information must be retained for legal or regulatory reasons. If access is refused, we will provide a written statement of reasons unless it is unreasonable to do so.
How we handle requests to correct your Personal Information and Sensitive Information
We will take such steps (if any) as are reasonable in the circumstances to make sure that the information we collect, use or disclose is accurate, complete, up to date and relevant for the purpose of its use or disclosure.
If you believe the information that we hold about you is inaccurate, irrelevant, out of date or incomplete, you can ask us to update or correct it. To do so, please contact us using the contact details listed below.
How to contact us or make a complaint
If you have any questions about this Privacy Policy, if you wish to correct or update information we hold about you or if you wish to request access or correction of your Personal Information or make a complaint about a breach by us of our privacy obligations (including the way we have collected, disclosed or used your Personal Information and Sensitive Information), please contact:
Attention: Privacy officer, ZeroQuarry
Address: 137 Male St, Brighton, VIC
Email: privacy@zeroquarry.com
Telephone: 0449584608
We will acknowledge and investigate any complaint about the way we manage information as soon as practicable. We will take reasonable steps to remedy any failure to comply with our privacy obligations. If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the problem. We will take reasonable steps to remedy any failure to comply with our privacy obligations.
If you remain dissatisfied with the outcome, you may refer the matter to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au.