Skip to content
Legal

Privacy Policy

Last updated: 2 August 2026 · Applies to validly.com.au and the Validly platform

Validly ("Validly", "we", "us", "our") helps Australian businesses keep their compliance documents valid, ready, and easy to share. This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using Validly, you agree to the handling of personal information as described here.

1. The information we collect

We collect only the information we need to provide proof-readiness services:

  • Account information — name, email address, phone number, password (stored only as a secure hash), and organisation details.
  • Business records — the people, suppliers, assets, and locations you add, and the documents, expiry dates, issuers, and reference numbers you record or upload.
  • Sensitive information — where you choose to record it (see section 4).
  • Usage and technical information — IP address, device and browser type, and activity logs used to operate and secure the service.
  • Information from third parties — for example, business details returned by the Australian Business Register when you use ABN lookup.

2. How we use your information

We use personal information to:

  • operate the service and track document validity;
  • send reminders, requests, and notifications;
  • generate and share proof packs at your direction;
  • secure your account and detect misuse;
  • provide customer support;
  • improve and develop the service; and
  • meet our legal obligations.

3. Sensitive information

Some records — such as Working with Children Checks, police checks, and health-related certificates — are sensitive information under the Privacy Act. Where you record sensitive information about an individual, you confirm that you have the authority and a lawful basis to do so. For restricted checks such as WWCC and police checks, Validly's default is to capture the status and expiry rather than store a copy of the document.

4. Disclosure and our service providers

We do not sell personal information. We share it only as needed to run the service, with vetted providers acting on our instructions, or where required by law. Our current categories of providers are:

  • Database hosting — Neon (PostgreSQL), hosted in the Sydney, Australia region.
  • File storage — Cloudflare R2, used to store uploaded documents.
  • Email delivery — MailerSend, used to send verification codes, requests, and reminders.
  • Product analytics — Vercel Analytics, used to understand aggregate usage.
  • Business lookups — the Australian Business Register, when you use ABN lookup.

We may also disclose information to comply with the law, enforce our terms, or protect the safety and rights of people.

5. Where your data is stored

Your account database is hosted in Australia (Sydney region). Some providers listed above may process limited data outside Australia. Where that occurs, we take reasonable steps to ensure the information is protected in a way consistent with the APPs, as required by APP 8.

6. Security

We take reasonable steps to protect personal information, including:

  • encryption in transit (HTTPS/TLS) and encryption at rest;
  • additional encryption of sensitive identifiers such as document numbers;
  • private file storage served only through time-limited, signed links;
  • role-based access controls and tenant isolation between organisations;
  • optional two-factor authentication for administrators; and
  • audit logging of key actions.

No system is completely secure, and we cannot guarantee absolute security, but we work to protect your information and to respond quickly if an issue arises.

7. Data retention

We keep personal information for as long as your account is active and as needed to provide the service. When you close your account, we delete or de-identify your personal information within 30 days, except where we are required to retain it by law. Audit logs may be retained for up to 7 years, and information held in encrypted backups may persist for up to 90 days before being overwritten.

8. We do not use your data to train AI

Your documents and business information are yours. We do not use them to train machine-learning or AI models, and we do not sell or share them for advertising.

9. Your rights

You may, at any time:

  • request access to the personal information we hold about you;
  • ask us to correct information that is inaccurate or out of date;
  • request deletion of your information or closure of your account;
  • export your organisation's data; and
  • opt out of non-essential communications.

To exercise any of these rights, contact us using the details below. We will respond within a reasonable time and in line with our obligations under the Privacy Act.

10. Data breaches

We maintain processes to detect and respond to data breaches. If a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.

11. Cookies and analytics

We use essential cookies to keep you signed in and to keep the service secure, and privacy-conscious analytics to understand aggregate usage. We do not use cookies for third-party advertising.

12. Changes to this policy

We may update this policy from time to time. We will update the "last updated" date above and, where changes are significant, take reasonable steps to let you know.

13. Contact us and complaints

For privacy questions, to make a request, or to raise a complaint, contact us at privacy@validly.com.au. We will acknowledge and work to resolve your concern. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.