Legal
This Privacy & Cookie Policy explains how CyberDNA Pty Ltd (ABN 95 627 959 200), trading as CyberDNA and operating the FIKS.cloud service ("FIKS", "we", "us", "our"), collects, uses, discloses and protects personal information when you visit our websites, run a free Cloud Exposure Assessment, purchase a subscription or expert-services sprint, or otherwise interact with us.
We design our privacy and security controls to align with the SOC 2 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality and Privacy) and we handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where applicable, we also comply with the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
FIKS.cloud is a cloud exposure management platform built and operated by CyberDNA, an Australian security company. For the purposes of the GDPR, CyberDNA is the data controller of personal information collected through our websites and marketing, and acts as a data processor for the technical metadata you connect to the FIKS platform under your customer agreement and Data Processing Addendum.
Registered office: 459 Collins Street, Melbourne, Victoria 3000, Australia
Privacy contact: info@cyberdna.com.au
We collect only what we need to provide, secure and improve the service.
fiks_vid) and campaign parameters (UTM tags) that let us understand your path from free assessment to purchase, set only after you consent.We use personal information to: provide and operate FIKS and your assessment; process payments and manage subscriptions; provide support; secure our services and detect abuse; understand which marketing and product journeys work (including whether an assessment led to a purchase, or whether an existing customer is upgrading); meet legal, tax and accounting obligations; and, with your consent where required, send you relevant product and marketing communications.
Where the GDPR applies, we rely on: performance of a contract (to deliver the service you purchased), legitimate interests (to secure, operate and improve our services and understand attribution, balanced against your rights), consent (for non-essential cookies and marketing), and legal obligation (tax, accounting and lawful requests).
We use a small number of first-party cookies. We do not use third-party advertising or cross-site tracking cookies. Non-essential cookies are set only after you select Accept on our consent banner; if you select Decline, no identifiers are set and no attribution parameters are appended to your links.
| Cookie | Purpose | Type | Retention |
|---|---|---|---|
fiks_consent | Records your cookie choice (accept/decline) | Essential | 180 days |
fiks_vid | First-party visitor ID to understand your journey from assessment to purchase | Analytics (consent) | 180 days |
fiks_utm | Stores campaign source (UTM) so we can attribute how you found us | Analytics (consent) | 180 days |
fiks_first | Timestamp of your first visit | Analytics (consent) | 180 days |
Managing cookies: you can withdraw consent at any time by declining the banner, clearing cookies in your browser, or using your browser's privacy controls. Our checkout provider (Stripe) and CRM (HubSpot) may set their own cookies on their own pages, governed by their respective policies.
We do not sell your personal information. We share it only with: our vetted service providers (subprocessors, below) under contract; professional advisers (legal, accounting, auditors) under confidentiality; and government or law-enforcement bodies where legally required. If we are involved in a merger, acquisition or asset sale, personal information may be transferred subject to this policy.
We engage the following subprocessors to deliver the service. Each is bound by data-protection terms consistent with the SOC 2 Trust Services Criteria and applicable law.
| Subprocessor | Purpose | Data handled | Region |
|---|---|---|---|
| Stripe | Payment processing & subscription billing | Billing contact, payment token, tax status | AU / EU / US |
| HubSpot | CRM, marketing & support communications | Name, work email, company, activity | EU / US |
| Amazon Web Services (AWS) | Cloud hosting & infrastructure | Application & log data | Australia / EU |
| Microsoft Azure | Cloud hosting & infrastructure | Application & log data | Australia / EU |
A current list of subprocessors is available on request at info@cyberdna.com.au.
We primarily store and process personal information in Australian and European (EU) regions. Some subprocessors (such as Stripe and HubSpot) may process limited data in other countries, including the United States. Where personal information is transferred outside your jurisdiction, we use appropriate safeguards — including the EU Standard Contractual Clauses and equivalent mechanisms — and we take reasonable steps under APP 8 to ensure overseas recipients handle your information consistently with this policy.
We retain personal information only as long as necessary for the purposes it was collected, then delete or de-identify it. Indicative periods: account data for the life of your account plus up to 12 months; billing and tax records for 7 years (Australian legal requirement); cookie/attribution identifiers for up to 180 days; support communications for up to 24 months. Assessment metadata is retained per your customer agreement and deleted on request or account closure.
Consistent with the SOC 2 Security and Confidentiality criteria, we apply layered technical and organisational controls, including:
No method of transmission or storage is completely secure, but we work continuously to protect your information and to meet our obligations.
Australia (APPs): you may request access to, and correction of, the personal information we hold about you, and you may complain about how we handle it.
EU/UK (GDPR): you have rights to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): you have the right to know, access, delete and correct your personal information, and to opt out of "sale" or "sharing". We do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising your rights.
To exercise any right, email info@cyberdna.com.au. We will verify your identity and respond within the timeframe required by applicable law (generally 30 days).
We maintain an incident response process aligned with the SOC 2 Security criteria. Where a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme. Where the GDPR applies, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours.
FIKS is a business service not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
We may update this policy from time to time. Material changes will be posted here with an updated "Last updated" date and, where appropriate, communicated to you directly. Please review it periodically.
Questions, requests or complaints about privacy? Contact us at info@cyberdna.com.au or write to CyberDNA Pty Ltd, 459 Collins Street, Melbourne, Victoria 3000, Australia.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au, or, in the EU/UK, your local data protection supervisory authority.