Preventionlabs
The Problem How It Works What You Get Pricing Dictionary

Privacy Policy

Effective 3 October 2026

This policy explains how Preventionlabs collects, uses, stores, and protects personal information. We comply with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth) and our obligations under the Australian Consumer Law (Schedule 2, Competition and Consumer Act 2010).

1. Information We Collect

We collect only the information necessary to deliver our services:

  • Contact information: Your name, email address, and project or business name, provided when you contact us or engage our services.
  • Payment information: Bank transfer reference details for payment processing. We do not store bank account numbers, card numbers, or financial credentials.
  • Project information: Repository links, source code, configuration, databases, and access to hosting or other accounts that you provide for the assessment or resurrection. This is provided by you and used solely for delivering the engagement.
  • Communications: Emails and messages exchanged during the engagement.

Your project may contain personal information about your own users. We handle it as described in Section 4.

We do not collect sensitive information as defined under the Privacy Act 1988 (such as health information, racial or ethnic origin, political opinions, religious beliefs, or biometric data).

2. How We Collect Information

We collect personal information in the following ways:

  • Directly from you: When you submit a project via the website form or email, give us access to your code or systems, enter into an engagement, or communicate with us during an engagement.
  • From publicly available sources: We may collect business contact information (name, email address, job title, company or project name) from publicly available sources such as business websites, public project pages, public directories, and professional networking platforms for the purpose of offering our services. This collection is consistent with APP 3.6 and is limited to information that has been made publicly available in a business context.

We do not purchase data from data brokers or use automated scraping tools to collect personal information.

3. Purpose of Collection

We collect and use your information for the following purposes only (APP 6):

  • Delivering the free assessment or the resurrection you engaged us for
  • Communicating with you about the engagement
  • Processing your payment
  • Complying with legal obligations (tax records, dispute resolution)

We will not use your information for any purpose other than the reason it was collected, unless you give us written consent or we are required to do so by law.

4. Your Code and Your Users' Data

  • We work on copies, test environments, and test data wherever practical.
  • We access real user data in your systems only where the engagement requires it, and only as far as needed.
  • We do not use your users' personal information for any purpose other than delivering your engagement.
  • Your code, your diagnosis, and any findings are treated as strictly confidential and are never publicly disclosed without your written consent.
  • At handover, we remove our access to your systems and delete the credentials you shared with us.

5. Disclosure

We do not disclose your personal information to any third party except:

  • Service providers: Providers we use to run the website, receive email, and deliver the engagement, namely Cloudflare (website and project submission form), our email provider, and the AI-assisted development tools described in Section 7. They process information on our behalf.
  • Legal requirements: Where required by Australian law, a court order, or a lawful request by a regulatory authority (such as the Australian Taxation Office or the ACCC).
  • Professional advisors: Accountants or legal counsel, bound by their own professional confidentiality obligations, solely for tax compliance or dispute resolution purposes.

We do not sell, rent, or trade personal information. We do not share information with marketing platforms, analytics providers, or advertising networks.

Overseas disclosure (APP 8): Some of these service providers process information on servers outside Australia, including in the United States. Where this happens, we take reasonable steps to ensure the information is handled consistently with the Australian Privacy Principles.

6. Website

The Preventionlabs website is a static site hosted on Cloudflare Pages. It does not use cookies, tracking pixels, analytics scripts, or any form of user tracking. Fonts are loaded from Google Fonts, which means your browser connects to Google's servers when you view the site.

The website includes a project submission form that collects your name, email address, project name, where your code is located, and project details. This information is transmitted via a Cloudflare Worker, delivered to us as an email, and stored in Cloudflare KV (key-value storage) within our account for record-keeping.

7. AI-Assisted Development Tools

We use AI-assisted development tools to analyse, repair, and test code. Code, configuration, and related project information you provide may be processed by these tools on servers outside Australia, including in the United States. We provide these tools only with what is needed for your engagement and, where practical, use test or redacted data in place of your users' real data.

8. Data Security (APP 11)

We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure:

  • Your code, diagnosis, and project records are treated as strictly confidential and stored securely.
  • Communications are conducted via encrypted email where possible.
  • Access to client information is limited to the person working on your engagement.
  • Credentials you share with us are used only for your engagement and are deleted at handover.
  • We do not store client information on shared or cloud-based systems beyond what is necessary for email, the project submission form, the tools described in Section 7, and the repositories and accounts you provide.

9. Data Retention

  • Project data: Copies of your code and project materials are retained securely on local systems for our records. You may ask us to delete them at any time after handover, and we will, except where we are required by law to keep records.
  • Credentials and access: Removed and deleted at handover.
  • Diagnoses and Scopes of Work: A copy is retained for our records for 7 years for legal and tax compliance purposes, unless you request earlier deletion.
  • Contact information: Retained for the duration of our business relationship and for 7 years after the last engagement for tax compliance.
  • Payment records: Retained for at least 5 years, as required by Australian tax record-keeping law.

10. Access and Correction (APP 12 and APP 13)

You have the right to:

  • Access the personal information we hold about you. We will respond to access requests within 30 days.
  • Correct any personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will correct information within 30 days of your request.

To make an access or correction request, email contact@preventionlabs.com.au.

We will not charge you for making a request or for correcting information. We may charge a reasonable fee for providing access if the request requires substantial effort, and we will inform you of the fee before proceeding.

11. Complaints

If you believe we have breached the Australian Privacy Principles or mishandled your personal information, you may lodge a complaint:

  1. Contact us at contact@preventionlabs.com.au with details of your complaint. We will respond within 30 days.
  2. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by phone at 1300 363 992.

12. Notifiable Data Breaches

In the event of an eligible data breach as defined under Part IIIC of the Privacy Act 1988 (Notifiable Data Breaches scheme), we will:

  • Notify the OAIC as soon as practicable.
  • Notify affected individuals as soon as practicable.
  • Include in the notification: the nature of the breach, the information involved, and recommended steps for affected individuals.

13. Commercial Electronic Messages

Where we send commercial electronic messages (such as emails offering our services), we do so in compliance with the Spam Act 2003 (Cth). All commercial emails:

  • Clearly identify Preventionlabs as the sender
  • Include accurate contact information
  • Include a functional unsubscribe mechanism

If you request to unsubscribe, we will remove you from our outreach list within 5 business days and will not contact you again for marketing purposes.

14. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal obligations. The effective date at the top of this page indicates when the current version took effect. Material changes will be communicated directly to active clients.

15. Contact

For any questions about this privacy policy or your personal information:

Preventionlabs
Email: contact@preventionlabs.com.au
Location: Western Australia

© 2026 Preventionlabs. All rights reserved.
Home Dictionary Terms Privacy