Sentrient Pty Ltd (ABN 63 609 044 788) (“Sentrient”, “we”, “us”, “our”) is committed to protecting the privacy of personal information we collect and handle, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Privacy Policy explains what personal information we collect, how we collect, use, hold and disclose it, and how you can access, correct or make a complaint about your personal information.

Last reviewed: 1 July 2026

Overview

This policy covers three different kinds of personal information, depending on how you interact with Sentrient:

  • Platform data – personal information our clients (organisations that use the Sentrient platform) enter into the software about their own employees, contractors or members – for example, names, contact details, and HR or compliance records. When handling Platform Data, Sentrient acts on behalf of, and under the instructions of, our clients.
  • Account and administration data – personal information about the individuals who administer or use a client’s Sentrient account, such as system administrators and billing contacts.
  • Website and marketing data – personal information collected when you visit sentrient.com.au, request a demo, subscribe to our newsletter, or otherwise contact us directly.

Where this policy refers to “you”, it means the individual whose personal information is being handled – this may be an employee of one of our clients, an administrator of a client account, or a visitor to our website.

Inclusions

  1. Who we are
  2. The personal information we collect
  3. How we collect personal information
  4. How and why we use personal information
  5. How we disclose personal information
  6. Where your data is held
  7. Data security
  8. AI and your data
  9. Data retention and destruction
  10. Cookies and website analytics
  11. Your rights – access, correction and complaints
  12. Contact us
  13. Changes to this policy

 

1. Who we are

Sentrient Pty Ltd is an Australian-registered company (ABN 63 609 044 788), based in Melbourne, Victoria, providing Compliance, GRC and HR software to organisations across Australia.

2. The personal information we collect

Depending on your relationship with us, we may collect:

  • Platform data: names, contact details, dates of birth, employment details, HR and compliance records, training and policy acknowledgement records, and other information our clients choose to hold in Sentrient.
  • Account data: names, work email addresses, phone numbers and role or permission details of the individuals who administer or use a client’s account.
  • Website and marketing data: name, email address, phone number, company name and any other details you provide through an enquiry, demo request or newsletter sign-up, along with browsing information collected through cookies (see section 10).

3. How we collect personal information

We collect personal information:

  • directly from our clients, when they enter Platform Data into Sentrient;
  • directly from you, when you contact us, request a demo, or subscribe on our website;
  • automatically, through cookies and similar technologies when you visit our website (see section 10); and
  • from third parties, where you have authorised this or it is otherwise permitted by law.

4. How and why we use personal information

We use personal information to:

  • provide, maintain and support the Sentrient platform for our clients;
  • respond to enquiries and provide demonstrations of our software;
  • manage our relationship with clients, including billing and account administration;
  • improve and develop our products and services;
  • comply with our legal obligations, including under the Privacy Act 1988 (Cth); and
  • market our services to prospective clients, where you have not opted out.

We use AI in select areas of the Sentrient platform. See section 8 for how AI is governed and what this means for your data.

5. How we disclose personal information

We do not sell personal information. We may disclose personal information to:

  • Microsoft Azure, our cloud hosting provider, which stores Platform Data on servers located in Australia;
  • ZIRILIO, our independent security testing provider, during penetration testing of our infrastructure and applications;
  • SendGrid, our email delivery provider, which processes names and email addresses to send system-generated and transactional emails on our behalf;
  • Third party accounting and payroll systems (Xero, MYOB, NetSuite and HeroPay), only where a client chooses to enable an integration, and only to the extent necessary to operate it;
  • Our professional advisers, such as lawyers and auditors, where reasonably necessary; and
  • Regulators, law enforcement or other parties, where required or authorised by law.

Where we disclose Platform Data to a third party, we take reasonable steps to ensure it is handled securely and only for the purpose for which it was disclosed.

6. Where your data is held

Platform Data is hosted on Microsoft Azure servers in Australia and does not leave the country.

Some of the tools we use for website analytics and advertising (see section 10) are provided by companies based overseas, including the United States. This only affects website and marketing data – it does not involve Platform Data.

7. Data security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include encrypting data at rest and in transit, restricting access on a need-to-know basis, and maintaining certification to ISO 27001 (Information Security Management) and ISO 9001 (Quality Management), each independently audited on an ongoing basis. We also commission annual, independent penetration testing of our infrastructure and applications. Further detail is available in our IT Security & Due Diligence information at [sentrient.com.au/security-due-diligence].

If we experience a data breach that is likely to result in serious harm to affected individuals, we will notify those individuals and the Office of the Australian Information Commissioner (OAIC), in line with our obligations under the Notifiable Data Breaches scheme.

8. AI and your data

We use AI in select areas of the Sentrient platform, aimed at making our software more efficient and useful for clients.

Your compliance records, personal information, and any other Platform Data is never used to train, fine-tune or otherwise improve any AI or large language model – ours or a third party’s.

No client data is sent to or processed by any external AI system outside our secure environment.

We do not use AI to make fully automated decisions about individuals without human review.

If AI use is part of your organisation’s due diligence process, contact us using the details in section 12.

9. Data retention and destruction

We retain Platform Data for as long as a client’s Sentrient account remains active. If a client’s relationship with Sentrient ends, their instance of the software is made inactive and the data within it is deleted within three months, unless a longer period is required by law.

We retain website and marketing data only for as long as reasonably necessary for the purpose it was collected, or as required by law.

10. Cookies and website analytics

Our website uses cookies and similar technologies to operate correctly and to help us understand how visitors use our site. We use:

  • Google Analytics, to understand website traffic and usage;
  • Google Ads remarketing, to show you relevant ads on other websites after you’ve visited ours; and
  • the Meta (Facebook) Pixel, to measure the effectiveness of our Facebook and Instagram advertising.

These tools may collect information about your browsing activity and share it with Google or Meta, who may combine it with other information they hold about you. You can manage or opt out of these tools using your browser settings, the Google Ads Settings page, or Meta’s ad preferences.

We do not use website cookies to collect Platform Data.

11. Your rights – access, correction and complaints

If you are an employee, contractor or member of one of our clients, and your personal information is held in Sentrient as Platform Data, please contact your organisation directly to access or correct your information, as they control that data. We will assist our clients to respond to your request where needed.

If you are a website visitor, subscriber, or an administrator of a client account, you can request access to or correction of your personal information, or make a complaint about how we’ve handled it, by contacting us using the details in section 12.

We will respond to requests and complaints within a reasonable time. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

12. Contact us

If you have any questions about this Privacy Policy, or want to access, correct or make a complaint about your personal information, please contact us:

Sentrient Pty Ltd

Phone: 1300 040 589

Email: [email protected]

13. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always available at sentrient.com.au/privacy-policy, with the date it was last reviewed shown at the top of this page.