Privacy Policy
This policy explains what CISO AI collects, why, who else sees it, and how long we keep it. It covers the website, the briefing emails, the slide downloads, reader comments, contributions and the News API. CISO AI is operated by Cintelis Pty Limited, an Australian company, and this policy is written to meet the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Overview
CISO AI publishes cyber intelligence summaries and written analysis for security teams, operators and executives. Most of the site can be read without giving us anything at all: the briefings, the analysis, the slides on the page and the source hubs are open to everyone, with no account and no sign-in.
You give us information when you ask for something in return. Subscribing to the briefing, downloading a slide deck, posting a comment, contacting us, contributing, or subscribing to the News API. This policy says what happens to it in each case.
2. Information We Collect
We collect information in the following ways:
- The briefing list: your email address, the form or page it came from, when you first subscribed and when you last did. Nothing else. The briefing form asks for an address and nothing more.
- The contact form: your name, email and message. We do not send an acknowledgement to a contact message, deliberately, because echoing a stranger's text back to an address they chose would turn the form into a relay for spam.
- Sign-in and comments: if you sign in to comment on an analysis article, the name and email address you enter, the time you confirmed the address and the network address you confirmed it from, and the text of any comment you post. Comments are shown with your name and never with your email. Sign-in is handled by our authentication service at auth.cisoai.au. Every comment is read by a person before it appears, and that review copy, which includes your name, your address and your comment, is emailed to the site's editor.
- Slide downloads: some analysis articles offer their slide deck as a file. To get it you give a name and a work email, and we keep those together with which deck you asked for, when you asked for it, and when you downloaded it. We email you a link to the file and that link works for 30 days. Asking for a deck does not subscribe you to anything: the briefing is a separate tick box on the same form, and we add you to that list only if you tick it.
- Contributions: contributions are taken by Stripe on Stripe's own pages. We never see or hold your card number. Stripe passes us your email address, the amount and currency, and whatever you chose to enter in its three optional fields: a display name, whether to list you on the supporters page, and whether to add you to the briefing. We keep a record against your email holding your display name, how many times you have contributed, the total amount, and the dates of the first and most recent contribution.
- The supporters page: if you tick the box and give a display name, that name, any link you supply and the date of your first contribution are shown publicly. Your email address and the amount are never published. If you contribute without ticking it, or tick it without giving a name, nothing about you is shown.
- The platform waitlist: everyone who contributes is also added to a waitlist for the platform we are building, marked as a supporter. This is separate from the briefing list and being on it does not subscribe you to the briefing or to anything else. Ask us and we will take you off it.
- News API subscriptions: your email address, the plan you chose, and the state of the subscription as Stripe reports it. Your API key is shown to you once and we store only a one-way hash of it, so we cannot recover or resend it.
- Measurement: we run no analytics or advertising tags. There is no Google Analytics property, no Tag Manager and no advertising tag on any page, so nothing here builds a record of what you read. The pages you request still appear in our host's server logs, as they do for any website.
- Security checks: the briefing, contact, comment sign-in and slide download forms are protected by Cloudflare Turnstile. It examines how your browser behaves, and we send your network address to Cloudflare so it can judge whether the submission is automated.
- Embedded videos: some analysis articles embed a YouTube video. Nothing loads from YouTube until you press play: until then the page shows a still image we host ourselves. Once you press play the video comes from YouTube's privacy-enhanced player at youtube-nocookie.com, and Google's privacy policy applies to it. One analysis article embeds a news clip through CNBC's own player. That one loads with the page rather than on a click, so CNBC receives your network address and browser details when you open the article, and CNBC's privacy policy applies to the player.
- Resources loaded from other companies: every page loads typefaces from Google Fonts. Some of the framework guides also load icons from Cloudflare's public code network and a charting library from jsDelivr. Each of those companies receives your network address and browser details as a consequence of your browser fetching the file.
- Usage and device data: network address, browser type, device details, the page you arrived from, and how you move through the site and the briefing emails.
- Email delivery data: whether a message we sent you was delivered, bounced or was rejected. We do not put tracking pixels in our emails and we do not rewrite the links in them to record clicks.
Please do not send us sensitive personal information. We do not ask for government identifiers, health information or financial account details anywhere on this site, and we have no reason to hold them.
3. Cookies and Browser Storage
The site itself sets exactly one cookie:
- cisoai_member is set when you sign in to comment. It keeps you signed in for up to 30 days, cannot be read by scripts, is only sent over a secure connection, and is cleared the moment you use the sign-out link.
That is the only cookie this site sets. Nothing measures you across pages or between visits, which is why there is no cookie banner: there is nothing to ask you about. You can block or delete the sign-in cookie in your browser settings, and blocking it only means you cannot stay signed in to comment.
Two of the framework guides, the governance framework and the integrated security framework, remember which boxes you have ticked on their checklists. That is kept in your own browser, never sent to us, and clearing your browser data removes it.
4. How We Use Information
- Operate, maintain and improve the website and the briefing.
- Send the briefing, and the slide deck, sign-in link or receipt you asked for.
- Publish comments once a person has reviewed them, and publish the supporters page.
- Take contributions and run News API subscriptions, including the records a business must keep about money it receives.
- Understand which articles are read and which offers work, so we write more of what is useful.
- Respond to enquiries and support requests.
- Detect and stop automated abuse, spam and fraud.
- Meet our legal obligations and enforce our terms.
We do not use your information to build a profile of you for anyone else. The promotions on this site are plain links we place ourselves, not an advertising network: no third party chooses which of them you are shown, nothing follows you between sites, and clicking one tells the destination only what any link would.
5. Legal Basis and Consent
We collect personal information only where it is reasonably necessary for what we do, as the Australian Privacy Principles require. Where a law such as the European General Data Protection Regulation applies to you, we rely on your consent, on the necessity of performing a contract, on our legitimate interests in running and protecting the site, and on compliance with legal obligations.
Marketing email is sent only to people who asked for it. Paying us is not consent to be emailed: a contribution adds you to the briefing only if you ticked that box, and if you have previously unsubscribed we will not quietly put you back on.
7. Data Retention
We would rather tell you the actual periods than say "as long as necessary":
- Briefing subscription: kept until you unsubscribe. Unsubscribing deletes the record outright rather than flagging it.
- Slide download records: kept indefinitely so we know who holds which deck. The download link itself stops working after 30 days.
- Comments: a published comment stays published until you or we remove it. Comments awaiting review, and those not published, are kept.
- Contribution, supporter and waitlist records: kept indefinitely. Records of money received are also subject to the retention periods Australian tax and corporations law imposes.
- Sign-in sessions: up to 30 days, and immediately when you sign out.
- Contact messages: kept in our mailbox as ordinary correspondence.
You can ask us to delete any of these and we will, except where we are required to keep a record.
8. Security
We use administrative, technical and physical safeguards designed to protect information from unauthorised access, loss, misuse or disclosure. Email addresses are used in hashed form as record keys, API keys are stored only as hashes, card numbers never reach us, and the endpoints that read any list require a secret that is not published. No internet service can be guaranteed completely secure, and you use this one with that understanding. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
9. International Transfers
Cloudflare, Google and Stripe operate worldwide, so your information may be stored or processed outside Australia, including in the United States. We rely on those providers' contractual commitments and standard data protection terms for those transfers. Using this site means information about your visit will cross a border.
10. Your Choices and Rights
You may ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to the address below and we will respond within a reasonable period, and ordinarily within 30 days.
Every briefing email carries an unsubscribe link that works without signing in and deletes your record. Messages you asked for individually, such as a slide deck, a sign-in link or a payment receipt, carry no unsubscribe link because they are sent once in answer to something you did. You can leave the supporters page or the platform waitlist at any time by asking us.
11. Complaints
If you think we have mishandled your personal information, contact us first at admin@cisoai.au and we will investigate and reply. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or in writing to GPO Box 5288, Sydney NSW 2001.
12. Contact Us
Questions, requests and concerns about this policy go to admin@cisoai.au. The operator of this site is Cintelis Pty Limited, Australia.