← graften.io
LEGAL

Privacy Policy

Effective date: 10 July 2026  ·  Last updated: 10 July 2026  ·  Version 1.0

Summary: Graften is a B2B security and compliance platform. We collect business and technical data to provide our service. Your data is encrypted at rest using per-account encryption keys managed by AWS KMS and stored in Australia (ap-southeast-2) by default. We do not sell your data. We do not serve advertising.

1. Who we are

Graften ("Graften", "we", "us", "our") is a security and compliance platform for managed service providers and organisations. The platform is operated by Graften Pty Ltd, a company registered in Australia.

Contact: privacy@graften.io

2. Who this policy applies to

This policy applies to:

If you are a client of an MSP using Graften, your MSP is the primary data controller for your organisation's data. Graften acts as a data processor on their behalf.

3. Data we collect

3.1 Account data

DataPurposeBasis
Name, email address, password (hashed)Account creation and authenticationContract
Company name, ABN/NZBN/Companies House number, countryBilling identity, invoicing, fraud preventionContract / Legal obligation
Website URLAccount type verification (MSP vs direct)Legitimate interest
Payment method (tokenised)Subscription billing via StripeContract
MFA credentials (TOTP seed, encrypted)Account securityContract

3.2 Client and security posture data

When you use Graften to manage client security, we store:

3.3 Usage data

3.4 Data we do NOT collect

4. How we use your data

UseBasis
Providing the Graften platform and its featuresContract
Processing subscription paymentsContract
Sending transactional emails (account creation, invoices, alerts)Contract
Generating AI-assisted reports and vCISO outputs using Anthropic's APIContract / Legitimate interest
Verifying business numbers against ABR, NZBN, Companies House, and ACRAContract / Legitimate interest
Dark web monitoring via the HIBP API for domains you registerContract
Platform security, fraud prevention, and abuse detectionLegitimate interest
Improving the platform (aggregated, anonymised analytics only)Legitimate interest
Compliance with legal obligationsLegal obligation

5. AI features and data processing

Graften uses Anthropic's Claude API to power the vCISO chat, report generation, and AI-assisted analysis features. When you use these features:

We do not send personally identifiable end-user data (e.g., individual employee names or email addresses from your client's systems) to the AI API without explicit configuration by the subscriber.

6. Data storage and security

7. Who we share data with

Third partyPurposeData shared
Amazon Web ServicesCloud infrastructure, database, storage, KMSAll platform data (encrypted)
AnthropicAI-assisted featuresSecurity posture context (zero retention)
StripePayment processingBilling details, payment method
Have I Been PwnedDark web monitoringDomain names you register for monitoring
Australian Business RegisterABN validation at signupABN number only
New Zealand Companies OfficeNZBN validation at signupNZBN number only
Companies House (UK)Company number validation at signupCompany number only
ACRA (Singapore)UEN validation at signupUEN number only
PostmarkTransactional email deliveryEmail address, email content

We do not sell personal data to third parties. We do not share data with advertisers.

8. Data retention

Data typeRetention period
Account and subscriber dataDuration of subscription + 90 days after cancellation
Security posture and audit dataDuration of subscription + 90 days
Billing records7 years (legal obligation)
API request logs30 days
Error logs14 days
Backup snapshots7 days rolling

On account cancellation, you may request immediate deletion of your data by emailing privacy@graften.io. Billing records are retained as required by law.

9. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, email privacy@graften.io. We will respond within 30 days. For Australian users, you also have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).

10. Cookies and tracking

Graften uses only technically necessary cookies — specifically a session cookie for authentication purposes. We do not use advertising cookies, analytics cookies, or any third-party tracking. There is no cookie banner on graften.io because we do not set non-essential cookies.

11. Children's data

Graften is a B2B platform intended for business use. We do not knowingly collect personal data from individuals under 18 years of age. If you believe we have inadvertently collected such data, contact us at privacy@graften.io.

12. International data transfers

Graften's primary data store is in AWS ap-southeast-2 (Sydney, Australia). If you are located outside Australia, your data may be transferred to and stored in Australia. For UK/EU subscribers, we rely on standard contractual clauses for any data transfers outside the UK/EEA where applicable.

13. Changes to this policy

We will notify subscribers by email at least 14 days before making material changes to this policy. The current version is always available at graften.io/privacy.

14. Contact

Privacy questions, data requests, and complaints:
privacy@graften.io
Graften Pty Ltd, Australia