LEGAL

Privacy Policy

How we collect, use and protect your data

Last updated: 24 July 2026

1. Who We Are

Rilla Shield Defence Pty Ltd (ABN 80 678 733 950) ("we", "us", "our") is the data controller for the personal information collected through our website, applications and services ("Service"). We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the Notifiable Data Breaches (NDB) scheme.

If you have questions about this Privacy Policy or how we handle your data, contact us at legal@rillashield.com.au or for security matters at security@rillashield.app.

2. What Personal Data We Collect

We collect the following categories of personal data depending on how you use the Service:

  • Identity & contact: name, email address, phone number, business name, ABN, role
  • Account: login credentials (hashed), subscription plan, billing history, MFA settings
  • Usage & telemetry: scan history, feature usage, error logs, device type, browser, IP address, timestamps
  • User content: invoices, emails, photos, documents, bank account details, supplier names, phone numbers, domains and other files or inputs you upload for analysis
  • Communication: support messages, chat transcripts, feedback, and email records

We do not intentionally collect sensitive information (such as health information, racial or ethnic origin, or biometric data) unless you voluntarily provide it for a legitimate purpose. We do not knowingly collect personal data from children under 16.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Service delivery: to provide, maintain, secure and improve the Service; to process your scans, verify payees, generate reports and alerts
  • Security & fraud prevention: to detect, prevent and investigate fraud, abuse, security incidents and unauthorised access
  • AI processing: to run automated risk analysis and generate outputs. AI models are not trained on your uploaded data for general model improvement
  • Legitimate interests: to analyse product usage, improve features, conduct research and ensure platform integrity
  • Consent: for marketing communications (you can withdraw consent at any time)
  • Legal obligation: to comply with applicable laws, regulations, court orders, and lawful requests from authorities

4. Automated Decision-Making & AI

RILLA Shield uses automated systems, including artificial intelligence, to generate risk scores, verdicts, labels, alerts and reports about invoices, suppliers, bank accounts, domains, phone numbers and other subjects. These are decision-support outputs only and do not, by themselves, produce legal or similarly significant effects about you. You retain full control over whether to act on any Output.

If you believe an Output is inaccurate or unfair, contact us at legal@rillashield.com.au and we will review the matter.

5. Data Sharing & Recipients

We share personal data with the following categories of recipients only where necessary:

  • Service providers: hosting, cloud storage, analytics, email delivery, customer support, and security tooling. These providers are bound by confidentiality and security obligations
  • Payment processor (Stripe): for payment processing, subscription management, tax calculation, fraud prevention and invoicing. Stripe acts as an independent controller for its own processing. See Stripe's Privacy Policy
  • Professional advisers: legal, accounting, insurance and cyber-security providers where necessary
  • Authorities: where required by law, regulation, court order, or to protect our rights, property or safety

We do not sell your personal data to third parties for marketing purposes. We do not share your uploaded content for unrelated AI model training.

6. Data Residency & International Transfers

Our primary infrastructure is hosted in Australia (ap-southeast-2). Some service providers may process data in other countries (including the United States) to deliver parts of the Service. Where this occurs, we ensure appropriate safeguards are in place, such as standard contractual clauses, data processing agreements, and compliance with recognised privacy frameworks.

7. Data Retention

We retain your personal data for as long as necessary to provide the Service and fulfil the purposes outlined in this policy:

  • Account data is retained while your account is active
  • Uploaded files (invoices, photos, documents) are retained until you delete them or close your account
  • Billing records are retained for 7 years to meet Australian tax obligations
  • Usage logs and security audit records are retained for 12 months, then anonymised or deleted
  • Threat-intelligence indicators (such as hashed identifiers) may be retained longer where they are de-identified and used for fraud-prevention purposes

When data is no longer needed, we securely delete or anonymise it. Anonymised data may be retained for analytics and security research.

8. Security

We implement appropriate technical and organisational measures to protect your data, including:

  • TLS 1.3 encryption for data in transit
  • AES-256 encryption at rest for stored files and databases
  • Multi-factor authentication (MFA) and role-based access controls
  • Row-level security (RLS) and least-privilege access in our database
  • Immutable audit logging and security monitoring
  • Regular security assessments, dependency scanning and incident response planning

While we take security seriously, no system is completely impenetrable. You are responsible for maintaining the confidentiality of your account credentials and for any activity under your account. Our breach response procedures are described in the Data Breach Policy.

9. Your Rights

Under the Privacy Act 1988 (Cth), you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate or incomplete data
  • Request deletion of your personal data (subject to legal retention requirements)
  • Opt out of direct marketing at any time
  • Complain about a breach of the Australian Privacy Principles or the NDB scheme

To exercise these rights, contact us at legal@rillashield.com.au. We will respond within 30 days. If you are unsatisfied, you may complain to the Office of the Australian Information Commissioner (OAIC).

10. Cookies & Tracking

We use cookies and similar technologies to operate the Service, remember your preferences, authenticate you, and analyse usage. For details about the cookies we use and how to manage them, see our Cookie Policy.

11. Direct Marketing

We may send you information about product updates, security tips, and offers if you have consented or if you are a business customer and the marketing is relevant to our existing relationship. You can opt out at any time by clicking the unsubscribe link or emailing legal@rillashield.com.au.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or through the Service. The "Last updated" date at the top of this page reflects the most recent revision. Continued use after the changes take effect constitutes acceptance.