← Back to ChainShield

Privacy Policy

Last updated: 28 May 2026

1. Overview

Simplecore Pty Ltd (ACN 641 930 627, ABN 39 641 930 627), which operates the ChainShield platform ("we", "us", "our"), is committed to protecting personal information in accordance with the Privacy Act 1988(Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, disclose, and protect personal information through the ChainShield platform ("Platform"). "ChainShield" is a registered business name (registered with ASIC on 28 May 2026) held by Simplecore Pty Ltd; references to ChainShield mean Simplecore Pty Ltd trading as ChainShield.

2. Information We Collect

2.1 Account Information

When you register for the Platform, we collect:

  • Name and email address
  • Organisation name and role
  • Authentication credentials (securely hashed, never stored in plain text)
  • Multi-factor authentication configuration

2.2 Vendor Data (Open Source)

The Platform collects information about third-party vendors from publicly available sources only. This may include:

  • Domain names, IP addresses, and network infrastructure details
  • Published vulnerability data (CVEs)
  • Business registration data from the Australian Business Register
  • Public news articles and media reports
  • SSL/TLS certificate details

This vendor data is collected from public sources and generally does not constitute personal information under the Privacy Act. Where vendor data incidentally contains personal information (e.g., a contact email in a WHOIS record), we process it in accordance with APP 3 (collection of solicited personal information).

2.3 Assessment Responses

When your organisation sends assessment questionnaires to vendors through the Platform, vendors may provide responses that include personal information about their personnel. This information is collected at your organisation's direction, and your organisation is the primary data controller for this information under the Privacy Act.

2.4 Usage Data

We collect technical data about Platform usage, including:

  • Login timestamps and IP addresses (for security audit purposes)
  • Pages visited and features used (for service improvement)
  • Browser type and device information

2.5 Payment Information

Where you elect to pay by credit or debit card, payment is processed by our nominated payment processor (currently Stripe) under their own terms and privacy policy. We do not receive or store full card numbers or CVV codes. We retain only a payment-method token, the last four digits of the card, the card brand and expiry, the billing name and address, and transaction metadata necessary to operate and reconcile the subscription. Where you pay by bank transfer, we retain invoice and remittance information for accounting and audit purposes.

2.6 Sensitive Information (APP 3)

We do not solicit sensitive information (as defined in the Privacy Act, including information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation, health, or criminal record). If you provide sensitive information voluntarily (for example, in a free-text assessment response or note), you do so at your own discretion and you consent to us holding it solely to provide the Service to you. We ask that you do not enter sensitive information into the Platform unless strictly necessary for vendor risk management.

2.7 Government Identifiers (APP 9)

We do not adopt, use, or disclose any Australian Government identifier (such as a Tax File Number, Medicare number, or driver licence number) as our own identifier of an individual. We do not request government identifiers in the ordinary operation of the Platform.

2.8 Anonymity and Pseudonymity (APP 2)

The Platform is a B2B service that requires authenticated access tied to your organisation, so most interactions cannot be conducted anonymously. For general enquiries through our website or hello@chainshield.com.au, you may use a pseudonym where it is lawful and practicable for us to respond.

3. How We Use Information

We use collected information to:

  • Provide the Platform and its features (APP 6 — use for primary purpose)
  • Generate risk assessments and security analyses
  • Send service notifications, alerts, and assessment reminders
  • Maintain security and prevent unauthorised access
  • Comply with legal obligations, including responding to lawful requests from Australian regulators
  • Improve the Platform through aggregated, de-identified analytics and monitoring error trends

See section 6B for our direct-marketing position.

4. AI Processing

ChainShield's AI agents analyse open-source intelligence and vendor-scoped data. Questionnaire answers, vendor correspondence, stored contact records, account data, and your organisation's context never enter the AI layer. ChainShield analyst review notes steer the agents — never attributed to your organisation.

Processed by the AI layer

  • Publicly sourced vendor data (domains, CVEs, ABR records, discovered infrastructure)
  • Findings derived from public sources

Never processed by the AI layer

  • Account data (user names, email addresses)
  • Credentials and API keys
  • Assessment questionnaire responses containing personal information
  • Personally identifiable information (PII)
  • MFA secrets or authentication data

We do not use your data to train AI models.

5. Data Storage and Security

Platform data is stored in Supabase (PostgreSQL) hosted in Sydney, Australia (AWS ap-southeast-2). We implement:

  • Encryption in transit using TLS 1.2 or higher between your browser and the Platform, and between Platform components and underlying infrastructure
  • Encryption at rest using AES-256 for the primary database (managed by our hosting provider)
  • Application-layer AES-256-GCM encryption for stored third-party API keys
  • Row-level security (RLS) for tenant data isolation
  • Multi-factor authentication support
  • Audit logging of administrative actions
  • Role-based access controls (system admin, MSP admin, org admin, user)

The Platform also uses Vercel for application hosting (Next.js edge and serverless functions) and Upstash for queuing and caching. These services are subject to separate data processing agreements.

While we take reasonable steps to protect your information (APP 11), no system is completely secure. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act.

6. Data Sharing and Disclosure

We may share personal information with:

  • Your MSP: If your organisation is managed by an MSP through ChainShield, your MSP administrator may access your organisation's data as part of their service arrangement
  • Service providers: Third-party services that help us operate the Platform, under appropriate data processing agreements:
    • Hosting: Vercel (application)
    • Database: Supabase (primary storage, Sydney)
    • Queue: Upstash (Redis) — operational metadata only (job queues, scan/agent execution state); no account data, assessment responses, internal notes, or credentials
    • Email: Resend (recipient addresses and the content of notifications and assessment invitations)
    • Payments: Stripe (card-billing customers only — payment-method token, last four digits, expiry, billing name and address; we do not receive full card numbers)
  • AI processing: AI-driven narrative generation — see section 4 for what data reaches the AI layer.
  • OSINT scanning: Vendor discovery scans are performed by a ChainShield-operated bbot scanner co-located with our production infrastructure. No third-party scanner host receives customer or vendor data.
  • Error & performance monitoring: handled entirely by ChainShield's own infrastructure (onshore). No third-party error-monitoring or performance-monitoring subprocessor receives data.
  • Regulators: Australian regulatory authorities when required by law (e.g., APRA, OAIC, ASD)
  • Legal proceedings: Where required by court order or legal process
  • Business transfer: In connection with a sale, merger, restructure, or insolvency of our business, in which case the recipient will be bound by privacy protections at least as protective as those in this Policy.

Cross-border disclosure (APP 8).Primary Customer Data is stored in Australia (Supabase, AWS Sydney ap-southeast-2). The following subprocessors operate or may route data through regions outside Australia: Vercel (application hosting and edge functions — global edge network, headquartered in the United States); Upstash (Redis queue / cache — operational metadata only; provider operates globally, headquartered in the United States); Resend (email delivery — recipient address and message content; provider operates globally, headquartered in the United States); Stripe (payment processing for card-billing customers — provider operates globally, headquartered in the United States; Stripe is the data controller for the payment instrument). Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles information in accordance with the Australian Privacy Principles, including through contractual data-protection commitments. Error and performance monitoring does not involve any overseas recipient — it is handled entirely by ChainShield's own infrastructure; no third-party monitoring subprocessor is engaged.

6A. Data Quality (APP 10)

We take reasonable steps to ensure that personal information we collect, use, or disclose is accurate, up to date, and complete, having regard to the purpose of use. You can update account information through the Platform settings at any time, or contact us at privacy@chainshield.com.au to correct information you cannot edit directly. Vendor data collected from public sources is refreshed on the Platform's standard scanning cadence; we do not warrant that public-source data is free from error.

6B. Direct Marketing

We do not sell personal information. We send transactional emails (such as service notifications, assessment reminders, security alerts, invoices, and product-update notices) as part of providing the Service. We will only send you marketing communications where we have your consent or where we are otherwise permitted to do so under the Spam Act 2003(Cth). Every marketing email contains a one-click unsubscribe option. You can also opt out of marketing at any time by emailing privacy@chainshield.com.au.

7. Data Retention

  • Account data: Retained for the duration of your subscription plus 90 days
  • Vendor scan data: Retained for 2 years for trend analysis, then archived
  • Audit logs: Retained for 24 months, after which they are automatically purged by our data retention cron
  • Assessment responses: Retained for the duration of your subscription; exportable on request

You may request deletion of your data at any time, subject to our legal retention obligations.

8. Your Rights

Under the Privacy Act, you have the right to:

  • Access: Request access to personal information we hold about you (APP 12)
  • Correction: Request correction of inaccurate or incomplete personal information (APP 13)
  • Complaint: Lodge a complaint about our handling of personal information
  • Data export: Request an export of your data in a machine-readable format

To exercise these rights, contact us at privacy@chainshield.com.au. We will respond within 30 days.

9. Cookies and Analytics

The Platform uses essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising pixels. Error and performance monitoring is handled entirely by ChainShield's own infrastructure, which collects: - Application errors and exceptions (for immediate incident response) - Performance metrics (page load times, transaction durations) - Browser and device information (for compatibility analysis) No third-party error-monitoring or performance-monitoring subprocessor is engaged — this data does not leave ChainShield's own infrastructure. It is collected in aggregate form for system health monitoring and does not include personal information by default. Session replay is not used — the Platform does not record or capture user interactions for playback. Analytics data is collected in aggregate form only and cannot be used to identify individual users.

10. Children

The Platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or through the Platform. The current version is always available at this URL.

12. Contact and Complaints

For privacy enquiries or complaints:
Privacy Officer: privacy@chainshield.com.au
Entity: Simplecore Pty Ltd (ACN 641 930 627, ABN 39 641 930 627) trading as ChainShield
Postal address: PO Box 273, Lawnton QLD 4501, Australia

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

See also: Terms of Service | Security Statement