Privacy Statement
How Techly handles personal information in Pyron and on its websites. Scoped to Australia and India.
| SCOPE OF THIS VERSION This Statement covers Australia and India. Material addressing the General Data Protection Regulation, UK GDPR, standard contractual clauses, New Zealand and Singapore is held in a dormant annexure and is not part of this Statement. Where a customer in another jurisdiction is contracted, a separate addendum is required. |
|---|
1. Who we are
Pyron is operated by Techly Operations Pty Ltd ACN 649 834 506, ABN 97 649 834 506. Pyron intellectual property is owned by Techly Holdings Pty Ltd ACN 649 834 275 and licensed exclusively to Techly Operations Pty Ltd, which may sublicense only as expressly authorised under that licence.
The Data Protection Officer is a director of Techly Operations Pty Ltd and may be contacted at Teams@techly.au.
2. What this Statement covers
- Personal information you give us directly — enquiries, account registration, support requests, and our websites.
- Personal information recorded in a Pyron tenant by one of our customers. For that information, our customer decides what is collected and why. We process it on their instructions. If you are asking about your own record in a customer's tenant, contact that organisation first.
3. The two roles we hold
| Information | Our role | What it means |
|---|---|---|
| Customer Data — Entries, forms, attachments and everything recorded in a customer tenant | Processor. Data Processor under India's DPDP Act 2023. | We act on the customer's instructions. We do not decide what is collected, we do not use it for our own purposes, and we do not delete or move it without instruction. |
| Platform-Generated Data — Audit Trail records, system logs, telemetry | Controller | We decide the purpose. This data is owned by Techly Holdings Pty Ltd. |
| Derived Data and Aggregated De-identified Data | Controller | Customers may opt out of contributing to aggregated data. The election is recorded on their Order Form. |
| Our own business contacts, enquiries and website visitors | Controller | Handled under this Statement in the ordinary way. |
The Privacy Act 1988 (Cth) uses the term APP entity rather than controller and processor. We use those terms here because they are required by Indian law and expected in procurement. Using them does not reduce our obligations under the Privacy Act.
4. What we collect and why
| Purpose | Information |
|---|---|
| Providing Pyron | Account identifiers, authentication data, role and permission assignments, activity records |
| Support | Contact details, correspondence, and the information you give us about an issue |
| Security and audit | Audit Trail records, access logs, IP address at the point of authentication, device information |
| Billing and administration | Contact and billing details of customer personnel |
| Enquiries and marketing | Name, organisation, contact details, and the content of your enquiry |
5. Where your information is held
Each Pyron tenant is provisioned in a designated region recorded in its Order Form. Australian tenants are hosted in Amazon Web Services Australian regions — Sydney (ap-southeast-2) primary and Melbourne (ap-southeast-4) secondary. No Customer Data is stored or processed outside the tenant's designated region. Google Cloud Platform is no longer used for production or backup workloads.
Each customer tenant is provisioned in a designated region recorded in that customer's Order Form, and no Customer Data is stored or processed outside it. Australian tenants are held in Australia. A change of region requires the customer's written instruction.
6. Who we share it with
- Service providers who process data on our behalf. The current list is published on our Trust Centre with a dated change log.
- Amazon Web Services, which hosts Pyron and supplies the Amazon Bedrock service used by Pyron AI.
- Where required or authorised by law, or to a law enforcement or regulatory body acting within its powers.
- We do not sell personal information and we do not disclose it for another party's marketing.
7. Pyron AI
- Pyron AI is supplied through Amazon Bedrock using Anthropic Claude models.
- Customer Data is not used to train foundation models and is not shared with the model provider for training.
- Inference is pinned to the endpoint in the tenant's designated region. Cross-region inference profiles are not enabled.
- Pyron AI operates inside the platform's permission model. It sees only what the person asking is already permitted to see, and its activity is recorded in the Audit Trail like any other actor.
- Pyron AI drafts; a person approves. Output that creates, alters or advances a record is reviewed by an authorised person before it takes effect.
8. Automated decisions
Some processing in our platforms happens without a person involved at the point of action. We describe it here because from 10 December 2026 the Privacy and Other Legislation Amendment Act 2024 (Cth) requires it, and because we would rather tell you than have you discover it.
| What happens | Information used | Effect on you |
|---|---|---|
| LogSec licence validation. A security licence is checked against the Victoria Police Licensing and Regulation Division. | Name, licence number and status. | A failed check prevents sign-on to a shift. We supply the validation result; your employer makes the employment decision, and their supervisor process is the route to human review. |
| Flow Graph Engine business rules. Rules configured by our customer attach workflows, route and prioritise records, advance stages and trigger notifications. | Whatever the customer records in the Entry, which may include your name, role, location and activity. | Depends on how the customer has configured it. The customer decides what those rules do and is responsible for providing a route to human review. |
| Pyron AI | Data the asking person is permitted to see. | None directly. Pyron AI drafts for approval; it does not decide. |
9. How long we keep it
- Audit Trail records: at least 24 months, and up to 7 years where a customer configures it.
- Customer Data: as configured by the customer, and for the subscription term. On termination, a 30-day export window, then deletion within 90 days. Backup sets are deleted on their normal rotation and remain encrypted and inaccessible until then.
- System logs: at least 12 months.
- Enquiries and business contacts: 7 years, or until you ask us to remove them.
10. Security
Encryption at rest to AES-256 and in transit to a minimum of TLS 1.2. Multi-factor authentication for privileged access. Structural access enforcement through the platform's permission engine, whose default answer is no. An append-only Audit Trail that no role can edit, including our own administrators and directors.
11. If something goes wrong
We notify an affected customer of a suspected or confirmed security incident affecting their data without undue delay and no later than 48 hours. Where personal information is involved we assess whether an eligible data breach has occurred under Part IIIC of the Privacy Act 1988 (Cth), within 30 days and sooner where we can, and notify the Office of the Australian Information Commissioner and affected individuals where the test is met. Where we act as processor, the customer notifies the individuals.
12. Our websites
- We use essential cookies, and first-party analytics that we host ourselves within our own Australian cloud environment. Nothing is sent to a third-party analytics service.
- Our analytics do not set an identifying cookie and do not store your raw IP address. Because of that, we do not show a cookie banner. If we ever add a non-essential or third-party tag, we will introduce a consent mechanism before doing so.
- Details are in the Pyron Cookie Policy.
13. Marketing
We send marketing only to people who have opted in. We send product and service updates to existing customers on the basis of that business relationship. Every commercial electronic message identifies us and carries a working unsubscribe.
14. Your rights
- You may ask for access to, or correction of, personal information we hold about you as controller. Write to Teams@techly.au. We acknowledge within 5 business days and respond within 30 days. If we refuse access we tell you why, in writing, and how to complain.
- Where your information sits in a customer's tenant, contact that organisation. We will help them respond, but we will not respond on their behalf without their instruction.
- If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner.
15. India
- Where we offer services to Data Principals in India, the Digital Personal Data Protection Act 2023 applies regardless of where data is hosted.
- For Customer Data, our customer is the Data Fiduciary and we are a Data Processor.
- Our Grievance Officer is a director of Techly Operations Pty Ltd, contactable at Teams@techly.au. We acknowledge a grievance within 3 business days and resolve it within 15 days.
- We do not knowingly process the personal data of a person under 18 without verifiable parental consent, and we do not use personal data for tracking or behavioural advertising directed at children.
16. Changes
We update this Statement when our processing changes. Material changes are notified to customers and posted on our Trust Centre with a dated change log. The version and effective date appear on the first page.
17. Contact
Techly Operations Pty Ltd, 15A Alden Court, Cheltenham VIC 3192. Teams@techly.au.
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 2.0 | Aug 2026 | Techly Operations Pty Ltd | Drafted; not issued. 48 confirmation markers. |
| 2.1 | 14 Aug 2026 | Techly Operations Pty Ltd | Issued. All confirmation markers closed. Residency restated per tenant. Automated decision-making disclosed at Part 8 ahead of the 10 December 2026 commencement. Analytics recorded as self-hosted and first-party. India Grievance Officer function added. Scope reduced to Australia and India, with other jurisdictions moved to a dormant annexure. |
Approval
Aden McCusker – Director – Techly Operations Pty Ltd
Date: [to be signed]
Jagjit Prithpal Saluja – Director – Techly Operations Pty Ltd
Date: [to be signed]
Pyron intellectual property is owned by Techly Holdings Pty Ltd and licensed exclusively to Techly Operations Pty Ltd, which may sublicense only as expressly authorised under that licence.
Enquiries: Teams@techly.au