Summary: Graften is a B2B security and compliance platform. We collect business and technical data to provide our service. Your data is encrypted at rest using per-account encryption keys managed by AWS KMS and stored in Australia (ap-southeast-2) by default. We do not sell your data. We do not serve advertising.
Graften ("Graften", "we", "us", "our") is a security and compliance platform for managed service providers and organisations. The platform is operated by Graften Pty Ltd, a company registered in Australia.
Contact: privacy@graften.io
This policy applies to:
If you are a client of an MSP using Graften, your MSP is the primary data controller for your organisation's data. Graften acts as a data processor on their behalf.
| Data | Purpose | Basis |
|---|---|---|
| Name, email address, password (hashed) | Account creation and authentication | Contract |
| Company name, ABN/NZBN/Companies House number, country | Billing identity, invoicing, fraud prevention | Contract / Legal obligation |
| Website URL | Account type verification (MSP vs direct) | Legitimate interest |
| Payment method (tokenised) | Subscription billing via Stripe | Contract |
| MFA credentials (TOTP seed, encrypted) | Account security | Contract |
When you use Graften to manage client security, we store:
| Use | Basis |
|---|---|
| Providing the Graften platform and its features | Contract |
| Processing subscription payments | Contract |
| Sending transactional emails (account creation, invoices, alerts) | Contract |
| Generating AI-assisted reports and vCISO outputs using Anthropic's API | Contract / Legitimate interest |
| Verifying business numbers against ABR, NZBN, Companies House, and ACRA | Contract / Legitimate interest |
| Dark web monitoring via the HIBP API for domains you register | Contract |
| Platform security, fraud prevention, and abuse detection | Legitimate interest |
| Improving the platform (aggregated, anonymised analytics only) | Legitimate interest |
| Compliance with legal obligations | Legal obligation |
Graften uses Anthropic's Claude API to power the vCISO chat, report generation, and AI-assisted analysis features. When you use these features:
We do not send personally identifiable end-user data (e.g., individual employee names or email addresses from your client's systems) to the AI API without explicit configuration by the subscriber.
| Third party | Purpose | Data shared |
|---|---|---|
| Amazon Web Services | Cloud infrastructure, database, storage, KMS | All platform data (encrypted) |
| Anthropic | AI-assisted features | Security posture context (zero retention) |
| Stripe | Payment processing | Billing details, payment method |
| Have I Been Pwned | Dark web monitoring | Domain names you register for monitoring |
| Australian Business Register | ABN validation at signup | ABN number only |
| New Zealand Companies Office | NZBN validation at signup | NZBN number only |
| Companies House (UK) | Company number validation at signup | Company number only |
| ACRA (Singapore) | UEN validation at signup | UEN number only |
| Postmark | Transactional email delivery | Email address, email content |
We do not sell personal data to third parties. We do not share data with advertisers.
| Data type | Retention period |
|---|---|
| Account and subscriber data | Duration of subscription + 90 days after cancellation |
| Security posture and audit data | Duration of subscription + 90 days |
| Billing records | 7 years (legal obligation) |
| API request logs | 30 days |
| Error logs | 14 days |
| Backup snapshots | 7 days rolling |
On account cancellation, you may request immediate deletion of your data by emailing privacy@graften.io. Billing records are retained as required by law.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, email privacy@graften.io. We will respond within 30 days. For Australian users, you also have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).
Graften uses only technically necessary cookies — specifically a session cookie for authentication purposes. We do not use advertising cookies, analytics cookies, or any third-party tracking. There is no cookie banner on graften.io because we do not set non-essential cookies.
Graften is a B2B platform intended for business use. We do not knowingly collect personal data from individuals under 18 years of age. If you believe we have inadvertently collected such data, contact us at privacy@graften.io.
Graften's primary data store is in AWS ap-southeast-2 (Sydney, Australia). If you are located outside Australia, your data may be transferred to and stored in Australia. For UK/EU subscribers, we rely on standard contractual clauses for any data transfers outside the UK/EEA where applicable.
We will notify subscribers by email at least 14 days before making material changes to this policy. The current version is always available at graften.io/privacy.
Privacy questions, data requests, and complaints:
privacy@graften.io
Graften Pty Ltd, Australia