Legal

Privacy Policy

Last updated: 24 August 2026 · Applies to aegoriq.com.au and all AegorIQ Services

In Plain English

We collect your name, email, business details and the website URL you submit (including for the free scorecard) so we can generate your risk report and deliver it to you. If you use the free scorecard and don't proceed to a paid report, we'll send you one follow-up email about it; after that, we won't email you again unless you opt in. We don't sell your data. We don't use pre-ticked marketing boxes. You can ask us to access, correct, or delete your information at any time.

1. About This Policy

This Privacy Policy explains how AegorIQ ("AegorIQ", "we", "us", "our"), a trading name of WNMC Holdings Pty Ltd (ABN 55 698 239 502), collects, holds, uses, and discloses personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy applies to information collected through aegoriq.com.au, our intake forms, email communications, and any other AegorIQ service channel.

2. What Personal Information We Collect

Depending on which Service you use, we may collect:

CategoryExamples
Contact detailsName, business name, email address, phone number
Business informationIndustry type, website platform, business location (state/territory)
Target Website informationThe URL you submit for review, and publicly accessible content of that website
Payment informationProcessed directly by Stripe. AegorIQ does not store full card details
Technical informationIP address and timestamp of form submissions, for security and audit purposes
CommunicationsAny information you provide when you contact us, including emails and form responses
Privacy Policy BuilderThe name and email address of the person completing the questionnaire, and which consents they gave and when. The answers you type into the questionnaire are encrypted in your browser before they reach us. We store the encrypted result so you can reopen the builder and change your answers during your 30-day window. The key that unlocks it travels only in your own link and never reaches our servers, so we hold a block of characters we cannot read, and we cannot recover it for you if you lose the link. It is deleted when the window closes. When you generate your policy we send a copy to the address you gave us; that copy passes through our mail provider and is not stored by us

3. How We Collect Personal Information

We collect personal information:

4. Why We Collect, Use and Disclose Personal Information

We collect, hold, use and disclose personal information for the following purposes:

We do not use or disclose personal information for any other purpose without your consent, unless required or authorised by law.

5. Disclosure to Third Parties

We may disclose personal information to the following categories of third parties, solely for the purposes described above:

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

5A. Partners, Referrals and Information We Receive About You

When a partner asks us to run a report for you

We work with IT providers, managed service providers, web developers and agencies who look after websites for their own clients. Where one of them asks us to run a report on a site they manage for you, they give us the details we need to do it, typically a contact name, an email address and the website address.

Where we receive your details that way:

When we refer you to someone else

A report sometimes identifies work we do not do: building or fixing a website, or a legal question about your obligations. We may suggest a web developer, a lawyer or another provider who can help.

We do not sell, rent or trade personal information, and we do not disclose it to anyone in exchange for a benefit.

6. Overseas Disclosure

Some of the third-party service providers listed in Section 5 (in particular our data storage provider (Airtable) and our hosting and infrastructure provider (Netlify)) store or process information on servers located outside Australia, including in the United States. Where this occurs, we take reasonable steps to ensure these providers handle personal information in a manner consistent with the Australian Privacy Principles, including through the providers' own privacy and security commitments and contractual data-protection terms.

7. Data Security and Retention

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure.

We don't keep things indefinitely. These are the actual periods, and they are enforced automatically:

WhatHow long we keep itWhy
Scan findings and website technical details, your report, re-scan results, and the record of the platform and components we detected on your site 24 months from delivery of your report So we can honour your re-scans, and tell you if a vulnerability later affects software we saw on your site. After 24 months this information is out of date and we delete it.
Purchase record. Your name, business name, email, the amount paid and the date 5 years from the transaction Australian tax law requires us to keep records of our sales. This is the minimum we can lawfully keep, and nothing more is retained with it.
Free Scorecard details, if you never proceed to a paid report 24 months So we don't re-scan or re-contact someone who has already told us no.
Returning-customer discount code 24 months, matching the life of the code The code is valid for two years; once it expires we no longer need to hold it.

When a retention period ends, the information is deleted or de-identified. You can ask us to delete your information sooner than these periods at any time, and we will, except for the purchase record, which we are legally required to keep.

7A. The Privacy Policy Builder

The Privacy Policy Builder is a separate product from our website reviews, and it handles information differently. Before the questionnaire begins we ask for your name and an email address, and for your agreement to this policy and to our terms. Agreeing to receive updates from us is optional and is recorded separately; the box is never ticked for you.

Your answers to the questionnaire are encrypted in your browser before they reach us. We store the encrypted result against your purchase so you can close the builder and carry on later from the same link. The key that unlocks it is part of that link and is never sent to our servers, so what we hold is a block of characters we have no way to read. Two consequences follow, and both are deliberate: we cannot recover your answers if you lose the link, for anyone, on any proof of purchase; and anyone you forward the link to can open your saved answers. The policy itself is assembled in your browser from what you type, and the stored copy is deleted when your 30-day window closes.

When you generate your policy we email a copy to the address you confirmed, so that you have one if the download is lost. To send it, the finished document passes through our email provider. We do not keep a copy. It is not written to our systems, and the only copies that exist afterwards are yours and the one in your inbox.

The person who pays is often not the person who fills in the questionnaire. Where the two email addresses differ we record that fact, so we know who to contact about the policy itself.

8. Marketing and Communications

We will only send you marketing communications (such as information about our other services or follow-up offers like a Fix Verification Re-scan) if you have provided your consent. We do not use pre-ticked consent boxes. Every marketing communication we send includes a functional unsubscribe mechanism, in accordance with the Spam Act 2003 (Cth). You can withdraw consent at any time by using the unsubscribe link or contacting us directly.

If you use the AegorIQ Free Scorecard, we may send you a single follow-up email referencing that scan and any time-limited discount offer associated with it. We treat this as a transactional communication directly related to the service you requested, rather than general marketing, consistent with the Spam Act 2003 (Cth)'s treatment of factual, transaction-related messages. This follow-up email also includes an unsubscribe mechanism, and we will not send further marketing communications beyond this single follow-up unless you separately opt in.

9. Automated Analysis and Artificial Intelligence

Your report is produced by automated analysis (our AI-assisted scanning engine). When you ask us to check a website, our systems examine its publicly available pages, configuration and public DNS records against a defined set of security and Australian-compliance checks, and generate the findings and score you receive. These checks are rule-based and applied consistently to every website we scan. For Expert reports, a qualified cybersecurity professional reviews the findings before the report is delivered to you.

We may also use artificial-intelligence tools to help write or summarise the plain-English explanations in our reports and guides, and to help us respond to your enquiries. Where we do, we do not submit any more of your personal information than is necessary, and we use reputable providers.

We do not use automated decision-making to make decisions that produce legal, or similarly significant, effects about you as an individual. Your report is advisory information and recommendations about a website; it does not approve, refuse, price, or otherwise decide anything about you personally. The automated decision-making transparency requirements added to the Privacy Act 1988 (Cth) (which apply from 10 December 2026 to certain automated decisions that significantly affect individuals) are therefore not engaged by how we currently operate. We will update this section if that changes.

If you have questions about how a particular finding in your report was generated, or about the automated analysis or AI tools we use, you can contact us using the details in Section 12 and we will provide a meaningful explanation of the general logic involved.

10. The Trust Badge and Verification Page

If you buy a report, we issue you a Trust Badge. This is the only part of our service that involves publishing information about you, so we set it out separately.

Nothing is published unless you choose to display the badge. Issuing a badge is not consent to publish it. Until you opt in, the badge image returns nothing and no verification page for your business exists on our site. Opting in is a deliberate step you take on your badge settings page, and one click turns it off again.

Once you opt in, your verification page becomes public and can be indexed by search engines. It shows:

It does not show your report, your score, your individual findings, your contact details, or anything you told us at intake.

To operate the badge we store, against your order: a badge identifier, the level and the figures it was calculated from, the reviewed domain, the issue, review and expiry dates, whether you have opted in, and when we last contacted you about it. When a visitor loads the badge on your website, our server receives that request in order to return the image; we do not set cookies through the badge, we do not place tracking code on your site, and we cannot identify your visitors.

Trust Wall. Separately, you may consent to being featured on our Trust Wall or social channels. That is a further, separate opt-in, and it covers your business name, logo, link and any quote you supply. You can withdraw it at any time by contacting us.

Turning it off and deletion. You can stop displaying the badge at any time, which removes the public verification page. If you ask us to delete your information, the badge and its verification page go with it. We keep the minimal purchase record where the law requires us to: see section 7.

The terms that govern displaying the badge are at aegoriq.com.au/badge-terms.

11. Cookies and Third-Party Services

Our website may use minimal cookies necessary for core functionality (such as remembering form progress). We do not use third-party advertising or tracking cookies.

Our website loads fonts from Google Fonts (fonts.googleapis.com), which may involve your browser connecting to Google's servers to retrieve font files. Google's privacy policy applies to this connection.

12. Access, Correction and Complaints

You may request access to, or correction of, the personal information we hold about you by contacting us using the details below. We will respond within a reasonable timeframe.

If you believe we have breached the Australian Privacy Principles, you can lodge a complaint with us directly. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

13. Contact Us

For privacy-related questions, access or correction requests, or complaints, please contact:

Email: contact@aegoriq.com.au
Trading name: AegorIQ, a trading name of WNMC Holdings Pty Ltd
ABN: 55 698 239 502

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements, including the Privacy Act reforms taking effect from December 2026. The updated policy will be posted on this page with a revised "Last updated" date.