| Who we are | 1ST2 Pty Ltd (ABN: 74 698 159 456), an Australian company providing AI-powered IT support, security, and compliance software-as-a-service to business customers. |
|---|---|
| What law applies | Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). |
| Where your data is held | Primary application data is hosted in Australia. Certain processing occurs overseas via approved sub-processors, as described below. |
| Contact | info@1st2.ai |
1ST2 Pty Ltd ("1ST2", "we", "us", "our") is an Australian software company providing the 1ST2 platform - an AI-powered IT support, security, and compliance service for small and medium businesses (SMBs) operating Microsoft 365 environments.
This Privacy Policy explains how 1ST2 collects, holds, uses, and discloses personal information in connection with our website (1st2.ai), the 1ST2 platform, and related services (the "Services").
This Policy applies to customers, authorised users of the platform, website visitors, and prospective customers. It does not apply to personal information our customers collect and process through their own systems - customers who process personal information through the 1ST2 platform do so as data controllers in their own right.
As controller - when we collect and use personal information for our own purposes (managing accounts, billing, communications, improving our Services), 1ST2 is the data controller.
As processor - when authorised users interact with the 1ST2 platform, personal information relating to your organisation's personnel may be processed by our systems on your behalf, strictly in accordance with our Subscription Agreement and Data Processing Agreement (DPA), provided at signup. We do not use customer personnel data for our own commercial purposes.
We do not knowingly collect sensitive information (as defined under the Privacy Act) except to the extent incidentally included in a query you submit. We do not knowingly collect information from individuals under 18.
| Purpose | Description |
|---|---|
| Service delivery | Operating and maintaining the platform, processing support requests, delivering reporting. |
| Account management | Managing subscriptions, billing, and account settings. |
| Security and integrity | Monitoring for abuse, detecting incidents, verifying identities. |
| Communications and support | Responding to enquiries, providing support, sending service notices. |
| Product improvement | Using aggregated, de-identified analytics to improve the Services. No individual personal information is used to train AI models without separate consent. |
| Marketing | Sending marketing communications subject to opt-in/opt-out, compliant with the Spam Act 2003 (Cth). |
| Legal compliance | Meeting obligations under Australian law. |
We do not sell personal information. We may disclose it to:
Some of our sub-processors are located overseas, including in the United States. Before disclosing personal information to overseas recipients, we take reasonable steps to ensure compliance with Australian Privacy Principle 8, including contractual protections with each sub-processor and limiting the information transferred to what is necessary for service delivery. Full detail is set out in our Data Processing Agreement, provided at signup.
We retain personal information only for as long as necessary for the purposes described in this Policy, or as required by law (for example, tax and corporate record-keeping obligations typically require 7 years). Full retention schedules by data category are set out in our Data Processing Agreement. After the applicable period, we securely delete or de-identify the information.
We apply industry-standard security measures, including encryption of data in transit and at rest, role-based access controls, multi-factor authentication requirements, and regular security testing.
1ST2 is subject to the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If we have reasonable grounds to believe an eligible data breach has occurred, we will contain and assess it, notify the OAIC where required, and notify affected individuals with a description of the breach and recommended steps. Where a breach relates to information processed on behalf of a customer, we will notify that customer promptly to assist them in meeting their own obligations.
Report a suspected breach: info@1st2.ai
The 1ST2 platform offers optional add-on security and backup modules (for example, endpoint detection and response, threat detection, security awareness training, patch management, and cloud backup) which are provided by independent third-party vendors. These modules are opt-in - they are not enabled unless you choose to activate them.
Where you opt in to a third-party module, that vendor will process relevant data as an independent provider under their own privacy policy and terms, in addition to our own Data Processing Agreement covering their role as a sub-processor. We will provide you with a plain-English description of each module and a link to the relevant vendor's terms and privacy policy before you activate it, and will record your acceptance or declination. We encourage you to review each vendor's own terms before opting in.
Our website and platform use cookies and similar technologies. Full details are set out in our Cookie Policy at 1st2.ai/cookies.
| info@1st2.ai | |
|---|---|
| Response time | Acknowledged within 5 business days; substantive response within 30 days. |
If unsatisfied with our response, you may contact the OAIC - www.oaic.gov.au, 1300 363 992.
We may update this Policy from time to time. The current version is always available at 1st2.ai/privacy. We will provide at least 14 days' notice of material changes to current customers.
This Policy is governed by the laws of South Australia and the Commonwealth of Australia.
| Field | Detail |
|---|---|
| Document owner | 1ST2 Pty Ltd |
| ABN | 74 698 159 456 |
| Version | 1.1 |
| Effective date | 9 July 2026 |