Privacy notice
Last updated
Who we are
Get Frank is a trading name; the operating company is being registered and its details will be added here once available. This notice explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. For any privacy question or request, contact us at privacy@getfrank.ly.
What we collect
We collect personal information directly from you, automatically as you use the site, and — where you are named in something a customer organisation puts into the platform — from that organisation rather than from you. The table below is a guide, not an exhaustive list.
| Information | How we collect it | Why we collect it |
|---|---|---|
| Contact and identity details — name, email, organisation | Directly, when you submit the contact form or correspond with us | Enquiry and marketing |
| Account details — your name, work email, organisation | Directly, when you or your organisation set up and use your account | Service delivery |
| The files and records a customer organisation uploads to the platform, which may contain personal information about its employees, contractors, suppliers, or other people | From that customer organisation, not from the individuals named in them | Service delivery |
| Usage and device information — pages viewed, referring site, browser and device type, country | Automatically, through Cloudflare Web Analytics when you visit the site | Analytics and improvement |
| IP address and browser or device security signals | Automatically, through Cloudflare Turnstile when you visit the contact page or use the form | Bot protection |
Everyone who uses the platform does so on an organisation’s behalf, and we deal with them as that organisation’s authorised representative. Putting a file or a record into the platform is a statement that the person doing it is entitled to act for the organisation, and that the organisation holds whatever permission it needs to give us what is in that file.
Information about people who are not our users
A governance record can name people who never dealt with us: the owner of a risk, the contact at a supplier, the person an incident concerns. If we hold information about you for that reason, we did not collect it from you, and this section is our notice of that collection.
We do not come to you for it directly because we have no way to. We hold no relationship with you and no means of reaching you; the organisation that engaged us holds both. No law requires us to collect it. The customer organisation decides what its records contain and what it puts into the platform, and we hold what it uploads to deliver the service to that organisation and for nothing else — the sub-processors, retention, and security sections below apply to it exactly as they do to anyone’s. If information about you is never uploaded, no consequence follows for you. You are not our customer and we owe you no service; any consequence is the customer organisation’s, in its own records.
Our agreement with each customer requires it to be entitled to supply what it uploads, and to have given the people named in it whatever notice they are owed. If you were not told, or you want to know what is held about you or have it corrected, ask that organisation first. It decides what its records contain and we will not alter them on your behalf. Come to us at privacy@getfrank.ly and we will tell you who holds it, help where we practicably can, and treat a complaint about our own handling under the complaints section below.
Sensitive information
We do not seek to collect sensitive information. As defined in the Privacy Act 1988 (Cth), this includes information about health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or criminal record. Please do not submit it through our contact form or in correspondence. Where we receive it there without having asked for it, we will destroy or de-identify it as soon as practicable, unless the law requires us to retain it.
The platform is not built to hold it either, and it should not reach the platform at all — though a governance record can carry it without anyone intending it to, in a health detail inside an incident narrative or a background check inside a supplier file. Customers decide what goes into an upload: remove or redact sensitive information before the file is uploaded. Where something has already reached us, raise a support request and we will remove it from working data.
How we use it
- To deliver a service you have engaged us for.
- To understand how the Get Frank platform is used, to troubleshoot issues, and to improve our services.
- To keep the service secure and to monitor and enforce compliance with our terms of service, including detecting and preventing misuse.
- To contact you about that service, or where you have opted in to marketing from us. You can opt out of marketing at any time through the unsubscribe link in any marketing email.
- We may share your details with the sub-processors listed below, for the purpose shown against each of them. We do not share your details with another party for their own use, except where required for compliance purposes or to comply with a valid legal request.
Cookies
We set no cookies of our own, and our analytics set none. Cloudflare Web Analytics counts page views without setting cookies, without writing to your browser’s local storage, and without fingerprinting your browser or device. It does not identify you, track you across sites, or track you over time. It derives a country from your IP address as the page loads; the analytics record keeps the country and not the address.
The Cloudflare Turnstile widget on our contact page is served by Cloudflare from its own domain and runs under Cloudflare’s own terms. To run and secure the challenge, Cloudflare may store data on your device, including cookies. We do not control what it stores and we do not read it. See the sub-processors table below for what Turnstile processes on our behalf.
Separately from analytics, Cloudflare receives your IP address whenever it serves you a page, and processes it to deliver and secure the site. You can block or delete stored data at any time through your browser settings, though blocking it may stop the contact form’s bot check from completing.
The Get Frank platform is a separate application from this website, and it does set one cookie: a strictly necessary cookie that keeps you signed in between visits. It is scoped to the platform’s own origin and is not sent to this website or to any other site. The platform sets no analytics or advertising cookies.
It also keeps two things in your browser’s own storage, both strictly necessary to run: the token that authenticates your signed-in session, and the state of what you were working on, so that reloading a page does not lose your place. Signing out clears the token; the view state is held per tab and goes when you close it.
Sub-processors
We rely on a small number of trusted providers to operate the service. We select providers that are subject to privacy and security obligations consistent with this notice, and require them by contract to protect the information they handle for us. Some hold data outside Australia; where they do, the country is shown below.
| Provider | Purpose | Where data is held |
|---|---|---|
| Application hosting — provider to confirm | Hosting the Get Frank application | Australia |
| Microsoft | Australia | |
| SMTP2GO | Contact-form email delivery | Australia |
| Cloudflare | Website hosting, analytics, and bot protection (Turnstile) | Globally |
Cloudflare operates a global edge network by design, serving the site from the location nearest to each visitor, so a fixed list of countries is not practicable. The locations shown reflect how we currently configure each provider and may change as the service evolves; we will update this table when it does.
When you visit the contact page or use the form, Cloudflare Turnstile processes your IP address and browser or device security signals on our behalf to tell humans from bots, and Cloudflare also uses those signals to improve its bot-detection service. We do not provide the contents of the contact form — your name, email, organisation, or message — to Cloudflare for this purpose.
Retention
- Data collected through a service with you is retained for the duration of our relationship with you.
- Files your organisation uploads to the platform are held only as long as your organisation’s retention window allows. That window is yours to set: it defaults to 30 days and cannot be set beyond 365, and there is no option to keep file contents indefinitely. Once it passes, the contents become eligible for removal and are erased by a cleanup that runs daily, so a file can remain in active storage until the first run after its window closes. The record of the upload — file name, size, content hash, and how its columns were mapped — is part of your assurance history and is kept.
- All other data — including contact form submissions, email correspondence, and analytics — is retained for up to 12 months.
Backups and what erasure means
When we erase something — because a retention window has passed, or because you asked us to — it is removed from the platform’s active storage, and the running application has no way to reach it afterwards.
That is not the same as removing every physical copy. A database backup taken while we still held the data continues to hold it until the backup itself expires, and restoring a backup restores what that backup held at the moment it was taken. We do not archive backups indefinitely, and we set backup retention so that it is never longer than the longest retention window in force for a customer. Until a backup expires, the data in it is used for nothing but restoring the service.
Security
We apply industry-standard controls to protect the information we hold on your behalf. Given what we do for a living, we treat this as foundational rather than incidental.
In practice that means traffic to and from the platform is encrypted in transit and served only over HTTPS; each customer’s data is isolated from every other customer’s at the database layer; credentials you give us for connected systems are encrypted at rest; and the privileged console we use to support the service runs on a separate origin from the application you use, so a session in one cannot be reached from the other.
Data breaches
If an eligible data breach occurs — one that is likely to result in serious harm to an affected individual — we will act to contain it and notify the affected individuals and the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme.
Children
Our services are built for organisations and the people who work in them. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, email privacy@getfrank.ly and we will delete it.
Dealing with us anonymously
You can interact with us anonymously or using a pseudonym where it is practicable for us to deal with you that way. Some interactions require us to verify your identity — for example, confirming that you own an account or actioning a privacy request — and we cannot proceed anonymously in those cases.
Automated decisions
We do not make decisions that affect you using solely automated processing of your personal information.
Your rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you may request access to the personal information we hold about you and correction of anything that is inaccurate, out of date, or incomplete. Beyond those statutory rights, we also choose to offer erasure, restriction, and portability of your information where it is practicable for us to provide them. Email privacy@getfrank.ly to exercise any of these. Where you ask us to erase something, the limits described under backups apply: we remove it from the platform’s active storage, and any backup copy goes when that backup expires.
Complaints
If you believe we have mishandled your personal information, tell us first at privacy@getfrank.ly. We will acknowledge your complaint within 5 business days and aim to give you a full response within 30 days. If you are not satisfied with our response, you can escalate the matter to the Office of the Australian Information Commissioner at oaic.gov.au.
Updates
We will update this notice as our services evolve. Monitor this page for the latest version.
— Get Frank