Legal

Privacy & Cookie Policy

Last updated: 20 July 2026 · Effective: 20 July 2026

This Privacy & Cookie Policy explains how CyberDNA Pty Ltd (ABN 95 627 959 200), trading as CyberDNA and operating the FIKS.cloud service ("FIKS", "we", "us", "our"), collects, uses, discloses and protects personal information when you visit our websites, run a free Cloud Exposure Assessment, purchase a subscription or expert-services sprint, or otherwise interact with us.

We design our privacy and security controls to align with the SOC 2 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality and Privacy) and we handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where applicable, we also comply with the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

1. Who we are

FIKS.cloud is a cloud exposure management platform built and operated by CyberDNA, an Australian security company. For the purposes of the GDPR, CyberDNA is the data controller of personal information collected through our websites and marketing, and acts as a data processor for the technical metadata you connect to the FIKS platform under your customer agreement and Data Processing Addendum.

Registered office: 459 Collins Street, Melbourne, Victoria 3000, Australia
Privacy contact: info@cyberdna.com.au

2. Information we collect

We collect only what we need to provide, secure and improve the service.

Information you give us

Information we collect automatically

Cloud assessment metadata

3. How & why we use your information

We use personal information to: provide and operate FIKS and your assessment; process payments and manage subscriptions; provide support; secure our services and detect abuse; understand which marketing and product journeys work (including whether an assessment led to a purchase, or whether an existing customer is upgrading); meet legal, tax and accounting obligations; and, with your consent where required, send you relevant product and marketing communications.

Legal bases (GDPR)

Where the GDPR applies, we rely on: performance of a contract (to deliver the service you purchased), legitimate interests (to secure, operate and improve our services and understand attribution, balanced against your rights), consent (for non-essential cookies and marketing), and legal obligation (tax, accounting and lawful requests).

4. Cookies & tracking

We use a small number of first-party cookies. We do not use third-party advertising or cross-site tracking cookies. Non-essential cookies are set only after you select Accept on our consent banner; if you select Decline, no identifiers are set and no attribution parameters are appended to your links.

CookiePurposeTypeRetention
fiks_consentRecords your cookie choice (accept/decline)Essential180 days
fiks_vidFirst-party visitor ID to understand your journey from assessment to purchaseAnalytics (consent)180 days
fiks_utmStores campaign source (UTM) so we can attribute how you found usAnalytics (consent)180 days
fiks_firstTimestamp of your first visitAnalytics (consent)180 days

Managing cookies: you can withdraw consent at any time by declining the banner, clearing cookies in your browser, or using your browser's privacy controls. Our checkout provider (Stripe) and CRM (HubSpot) may set their own cookies on their own pages, governed by their respective policies.

5. How we share your information

We do not sell your personal information. We share it only with: our vetted service providers (subprocessors, below) under contract; professional advisers (legal, accounting, auditors) under confidentiality; and government or law-enforcement bodies where legally required. If we are involved in a merger, acquisition or asset sale, personal information may be transferred subject to this policy.

6. Subprocessors

We engage the following subprocessors to deliver the service. Each is bound by data-protection terms consistent with the SOC 2 Trust Services Criteria and applicable law.

SubprocessorPurposeData handledRegion
StripePayment processing & subscription billingBilling contact, payment token, tax statusAU / EU / US
HubSpotCRM, marketing & support communicationsName, work email, company, activityEU / US
Amazon Web Services (AWS)Cloud hosting & infrastructureApplication & log dataAustralia / EU
Microsoft AzureCloud hosting & infrastructureApplication & log dataAustralia / EU

A current list of subprocessors is available on request at info@cyberdna.com.au.

7. International data transfers

We primarily store and process personal information in Australian and European (EU) regions. Some subprocessors (such as Stripe and HubSpot) may process limited data in other countries, including the United States. Where personal information is transferred outside your jurisdiction, we use appropriate safeguards — including the EU Standard Contractual Clauses and equivalent mechanisms — and we take reasonable steps under APP 8 to ensure overseas recipients handle your information consistently with this policy.

8. Data retention

We retain personal information only as long as necessary for the purposes it was collected, then delete or de-identify it. Indicative periods: account data for the life of your account plus up to 12 months; billing and tax records for 7 years (Australian legal requirement); cookie/attribution identifiers for up to 180 days; support communications for up to 24 months. Assessment metadata is retained per your customer agreement and deleted on request or account closure.

9. How we protect your information

Consistent with the SOC 2 Security and Confidentiality criteria, we apply layered technical and organisational controls, including:

No method of transmission or storage is completely secure, but we work continuously to protect your information and to meet our obligations.

10. Your rights

Australia (APPs): you may request access to, and correction of, the personal information we hold about you, and you may complain about how we handle it.

EU/UK (GDPR): you have rights to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority.

California (CCPA/CPRA): you have the right to know, access, delete and correct your personal information, and to opt out of "sale" or "sharing". We do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising your rights.

To exercise any right, email info@cyberdna.com.au. We will verify your identity and respond within the timeframe required by applicable law (generally 30 days).

11. Data breach notification

We maintain an incident response process aligned with the SOC 2 Security criteria. Where a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme. Where the GDPR applies, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours.

12. Children's privacy

FIKS is a business service not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. Material changes will be posted here with an updated "Last updated" date and, where appropriate, communicated to you directly. Please review it periodically.

14. Contact & complaints

Questions, requests or complaints about privacy? Contact us at info@cyberdna.com.au or write to CyberDNA Pty Ltd, 459 Collins Street, Melbourne, Victoria 3000, Australia.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au, or, in the EU/UK, your local data protection supervisory authority.