Notifiable Breach is operated by Released Pty Ltd.
ABN 93 628 576 027
Privacy and support: support@releasedgroup.com

PRIVACY & YOUR INFORMATION

Handle less.
Protect more.

Effective 9 September 2026. This policy explains how Released Pty Ltd handles information when you use Notifiable Breach.

Use the initial check without an account

The free initial check runs in your browser. Its five categorical answers remain in page memory by default. If you choose to keep them for sign-in, only those answers are stored in this browser tab for up to one hour. After sign-in, you can review and explicitly confirm them before saving to your account, or discard them. No incident narrative or personal details are included in this transfer. Normal hosting request logs may still be processed to serve the site.

Information the signed-in application uses

Sign in with ChatGPT supplies an account identifier and email, and may supply a display name. The application saves your organisation name, privacy contact, incident descriptions, assessment answers, decisions and revision history. Payment records include references, amounts and status; card details are handled by Stripe.

Minimise incident data

Describe categories of affected information rather than uploading or pasting names, account numbers, medical records, passwords or compromised datasets. This service does not need those records to guide an assessment.

Storage and access

Application records are stored in a GPT Sites-managed Cloudflare D1 database. Access is restricted by the signed-in account identifier. GPT Sites, its infrastructure providers and authorised service administrators may process data to operate the service. Processing may occur outside Australia. We do not promise Australian-only residency, Azure hosting, certification or automatic deletion.

Optional AI processing

AI summaries are optional and disabled until configured. When enabled, generating a summary requires consent to send the saved incident description, information types, containment and risk reasoning to OpenAI. The application requests non-storage of the response; this is not a guarantee of zero provider retention. Review the provider’s data terms before use.

Retention and deletion

Incident data and revisions remain available until you delete the incident. Deletion removes its content and revision history from the active application database. A minimal deletion record remains to track consumed assessment credits. Payment and account records remain for service operation and accounting. Provider backups may have separate retention. There is no automatic retention expiry. Contact support@releasedgroup.com to request account deletion or ask about retained records. Records needed for accounting, legal obligations or dispute resolution may be retained after a request.

Access, correction and complaints

Email support@releasedgroup.com to request access or correction, discuss deletion, or make a privacy complaint. We may verify your identity before providing account information. Explain your concern without sending compromised datasets. We will investigate and respond; if you remain dissatisfied, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.