Legal

    Privacy Policy

    Version 1.1 | Last Updated: 9 July 2026 | Effective Date: 9 July 2026
    Who we are1ST2 Pty Ltd (ABN: 74 698 159 456), an Australian company providing AI-powered IT support, security, and compliance software-as-a-service to business customers.
    What law appliesAustralian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
    Where your data is heldPrimary application data is hosted in Australia. Certain processing occurs overseas via approved sub-processors, as described below.
    Contactinfo@1st2.ai

    1. Introduction and Scope

    1ST2 Pty Ltd ("1ST2", "we", "us", "our") is an Australian software company providing the 1ST2 platform - an AI-powered IT support, security, and compliance service for small and medium businesses (SMBs) operating Microsoft 365 environments.

    This Privacy Policy explains how 1ST2 collects, holds, uses, and discloses personal information in connection with our website (1st2.ai), the 1ST2 platform, and related services (the "Services").

    This Policy applies to customers, authorised users of the platform, website visitors, and prospective customers. It does not apply to personal information our customers collect and process through their own systems - customers who process personal information through the 1ST2 platform do so as data controllers in their own right.

    2. Our Role: Controller and Processor

    As controller - when we collect and use personal information for our own purposes (managing accounts, billing, communications, improving our Services), 1ST2 is the data controller.

    As processor - when authorised users interact with the 1ST2 platform, personal information relating to your organisation's personnel may be processed by our systems on your behalf, strictly in accordance with our Subscription Agreement and Data Processing Agreement (DPA), provided at signup. We do not use customer personnel data for our own commercial purposes.

    3. What Personal Information We Collect

    • Account information: name, business email, organisation details, ABN, billing information, and Microsoft 365 tenant identifiers required to connect the platform to your environment.
    • Platform usage data: IT support ticket data, device information, compliance and security posture metrics retrieved via Microsoft's APIs, HR policy query logs (where enabled), and audit logs of platform activity.
    • Technical data: IP addresses, device identifiers, browser type, and log files generated during platform access.
    • Communications: content of any enquiries or support correspondence you send us.

    We do not knowingly collect sensitive information (as defined under the Privacy Act) except to the extent incidentally included in a query you submit. We do not knowingly collect information from individuals under 18.

    4. How We Collect Personal Information

    • Directly from you, when you register, submit support requests, or contact us;
    • From Microsoft, via authorised API access when you connect your Microsoft 365 tenant;
    • Automatically, through cookies and log files (see our Cookie Policy); and
    • From sub-processors and integrations, where those services return data as part of delivering the Services to you.

    5. How We Use Personal Information

    PurposeDescription
    Service deliveryOperating and maintaining the platform, processing support requests, delivering reporting.
    Account managementManaging subscriptions, billing, and account settings.
    Security and integrityMonitoring for abuse, detecting incidents, verifying identities.
    Communications and supportResponding to enquiries, providing support, sending service notices.
    Product improvementUsing aggregated, de-identified analytics to improve the Services. No individual personal information is used to train AI models without separate consent.
    MarketingSending marketing communications subject to opt-in/opt-out, compliant with the Spam Act 2003 (Cth).
    Legal complianceMeeting obligations under Australian law.

    6. Disclosure of Personal Information

    We do not sell personal information. We may disclose it to:

    • Approved sub-processors who support delivery of the Services, including providers of AI processing, cloud database and hosting infrastructure, and (where applicable) optional add-on security and backup modules. All sub-processors are bound by contractual obligations consistent with Australian privacy law. A full, current list of sub-processors is available on request or is provided as part of our Data Processing Agreement at signup.
    • Microsoft, to the extent required to operate Microsoft 365 integrations;
    • Professional advisers bound by confidentiality obligations;
    • Payment processors, for billing purposes;
    • Regulatory authorities or law enforcement, where required by law; and
    • A successor entity, in the event of a merger or sale, subject to equivalent privacy protections continuing to apply.

    7. Cross-Border Data Flows

    Some of our sub-processors are located overseas, including in the United States. Before disclosing personal information to overseas recipients, we take reasonable steps to ensure compliance with Australian Privacy Principle 8, including contractual protections with each sub-processor and limiting the information transferred to what is necessary for service delivery. Full detail is set out in our Data Processing Agreement, provided at signup.

    8. Data Retention

    We retain personal information only for as long as necessary for the purposes described in this Policy, or as required by law (for example, tax and corporate record-keeping obligations typically require 7 years). Full retention schedules by data category are set out in our Data Processing Agreement. After the applicable period, we securely delete or de-identify the information.

    9. Data Security

    We apply industry-standard security measures, including encryption of data in transit and at rest, role-based access controls, multi-factor authentication requirements, and regular security testing.

    10. Notifiable Data Breaches

    1ST2 is subject to the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If we have reasonable grounds to believe an eligible data breach has occurred, we will contain and assess it, notify the OAIC where required, and notify affected individuals with a description of the breach and recommended steps. Where a breach relates to information processed on behalf of a customer, we will notify that customer promptly to assist them in meeting their own obligations.

    Report a suspected breach: info@1st2.ai

    11. Your Rights

    • Access: you may request access to personal information we hold about you (response within 30 days).
    • Correction: you may request correction of inaccurate or out-of-date information.
    • Opt-out: you may opt out of marketing at any time.
    • Deletion: you may request deletion, subject to legitimate legal, contractual, or operational retention needs. Customer data is deleted from live systems within 30 days of subscription termination.
    • Complaints: contact us first (Section 14); if unresolved, you may escalate to the OAIC at www.oaic.gov.au.

    12. Optional Third-Party Security Applications

    The 1ST2 platform offers optional add-on security and backup modules (for example, endpoint detection and response, threat detection, security awareness training, patch management, and cloud backup) which are provided by independent third-party vendors. These modules are opt-in - they are not enabled unless you choose to activate them.

    Where you opt in to a third-party module, that vendor will process relevant data as an independent provider under their own privacy policy and terms, in addition to our own Data Processing Agreement covering their role as a sub-processor. We will provide you with a plain-English description of each module and a link to the relevant vendor's terms and privacy policy before you activate it, and will record your acceptance or declination. We encourage you to review each vendor's own terms before opting in.

    13. Cookies and Tracking

    Our website and platform use cookies and similar technologies. Full details are set out in our Cookie Policy at 1st2.ai/cookies.

    14. Contact Us and Complaints

    Emailinfo@1st2.ai
    Response timeAcknowledged within 5 business days; substantive response within 30 days.

    If unsatisfied with our response, you may contact the OAIC - www.oaic.gov.au, 1300 363 992.

    15. Changes to This Policy

    We may update this Policy from time to time. The current version is always available at 1st2.ai/privacy. We will provide at least 14 days' notice of material changes to current customers.

    16. Governing Law

    This Policy is governed by the laws of South Australia and the Commonwealth of Australia.

    FieldDetail
    Document owner1ST2 Pty Ltd
    ABN74 698 159 456
    Version1.1
    Effective date9 July 2026