CHECKMATEBY CNETS

Privacy Policy

Version 2026-10-11.2 · CNETS PTY LTD · Australia and New Zealand

Summary: Customers control the information they put into Checkmate; CNETS handles it on their behalf to provide the service. We don't sell personal information or use customer content to train public AI models. See also our Terms of Use and Disclaimers.

1. Who we are and scope

This Privacy Policy explains how CNETS PTY LTD (ABN 78 670 429 464) ("CNETS", "we", "us") collects, holds, uses and discloses personal information in connection with the Checkmate compliance platform, our websites, enquiry forms and related CNETS services (together, the "Service").

We handle personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme, and, where applicable, the Privacy Act 2020 (NZ), including the Information Privacy Principles (IPPs).

This Policy forms part of, and should be read together with, the Checkmate Terms of Use and Disclaimers. If there is any inconsistency regarding limitation of liability, the Terms prevail to the extent permitted by law.

2. Customer and CNETS roles

Each customer organisation using Checkmate decides what information about its staff, auditors, suppliers and other individuals is entered into its workspace, and for what purpose. For that information, the customer is the entity primarily responsible for collection, notice, consent and lawful use, and CNETS acts as a service provider handling the information on the customer's behalf and in accordance with its instructions and our agreement.

Customers are responsible for ensuring they have a lawful basis and have given any required notices before entering personal information into Checkmate, and for the accuracy and appropriateness of that information. Individuals wishing to access or correct information held in a customer workspace should first contact the relevant customer organisation; we will assist the customer as reasonably required.

CNETS handles account, billing, enquiry, support and platform security information as its own business information under this Policy.

3. Personal information we collect

Account and identity information: name, business email, position or designation, organisation, role and permissions, sign-in method, password hashes (we never see plain passwords), multi-factor and single sign-on identifiers.

Usage and security information: IP address, device and browser details, sign-in times, session information and audit logs of actions taken in the platform.

Training information: module assignments, completion dates, quiz attempts, scores and certificates.

Assurance and third-party information: auditor names, emails and access-pass activity; supplier contact details, questionnaire responses and certification details (for example ISO 27001 or SOC 2 references and expiry dates).

Enquiry information: details submitted through pricing, plan or access-request forms, including name, email, phone, organisation, position or designation and requirements.

Customer content: documents, registers, evidence files, risks, incidents and corrective actions which may reference individuals. We do not intentionally collect sensitive information (such as health information) and ask customers not to upload it unless necessary and lawful.

4. How we use personal information

To provide, operate, secure, maintain and support the Service; authenticate users; send invitations, notifications, reminders, compliance summaries and auditor or supplier links; respond to enquiries; provide CNETS compliance assistance services where engaged; manage billing and contracts; prevent fraud and misuse; comply with legal obligations; and improve the Service using aggregated or de-identified information.

We do not sell personal information. We do not use customer content for marketing. We may send business communications about the Service to customer contacts; you can opt out of marketing messages at any time.

5. AI features

Some features (for example the AI Assistant, document generation and training quiz generation) send relevant customer content to AI model providers through secure interfaces to produce a response. Customer content is not used by CNETS to train public AI models, and we use providers whose terms restrict use of submitted data for training.

AI output is general in nature, may be inaccurate and is a draft only. Users should not enter more personal information into AI features than necessary.

6. Service providers and overseas disclosure

We use trusted service providers to operate the Service, including cloud hosting and storage, transactional email delivery, AI model providers, and content delivery networks. They may only use personal information to provide services to us and are subject to confidentiality and security obligations.

Checkmate's standard platform is hosted on commercial cloud infrastructure, and personal information may be stored or processed outside Australia and New Zealand, including in the Asia-Pacific region and in other countries where our service providers or their delivery networks operate. By using the Service, customers acknowledge this. We take reasonable steps so that overseas recipients handle information consistently with the APPs and IPPs.

Why this is appropriate for most organisations: neither the Australian Privacy Act 1988 (including APP 8) nor the New Zealand Privacy Act 2020 (including IPP 12) generally requires private-sector or non-government information to be stored within Australia or New Zealand. Overseas storage and processing is permitted where the organisation is open about it and takes reasonable steps to ensure the information is protected to a comparable standard. Checkmate supports this through transparent disclosure in this Policy and our Terms, contractual confidentiality and security obligations on service providers, encryption in transit and at rest, tenant isolation and restricted administrative access. Commercial businesses, not-for-profits and other non-government organisations can therefore generally use the standard platform for their privacy and ISO compliance programs. Each customer remains responsible for confirming that this arrangement meets its own contractual, industry and legal obligations.

Standard plans do not include dedicated or jurisdiction-specific hosting. Government, defence and regulated government bodies with specific hosting, sovereignty or security assessment requirements must engage CNETS on a Custom plan (tailored hosting, IRAP/ISM alignment and custom SLAs) and must not rely on standard plans for those requirements.

We may also disclose personal information where required or authorised by law, to professional advisers, to protect our rights or the safety of others, or in connection with a restructure, sale or transfer of our business, subject to confidentiality obligations.

7. Security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, including encryption in transit and at rest, tenant isolation, role-based access controls, short-lived links for private files, and audit logging.

No system is completely secure. Customers are responsible for managing their users, permissions, passwords, single sign-on settings and devices. To the maximum extent permitted by law, CNETS is not liable for unauthorised access resulting from customer-side credentials, configurations or third-party systems outside our reasonable control.

8. Data breaches

If we become aware of a data breach affecting information we hold, we will assess it promptly and, where required, notify affected customers, individuals and the Office of the Australian Information Commissioner (OAIC) and/or the New Zealand Office of the Privacy Commissioner in accordance with applicable law. Where information is held for a customer, we will cooperate with the customer, who will generally be responsible for notifying its own staff and contacts.

9. Retention and deletion

We keep personal information for as long as needed to provide the Service, meet contractual, legal, audit and record-keeping obligations, and resolve disputes. When a subscription ends, customer content is retained for a limited period to allow export and is then deleted or de-identified, except where retention is required by law or backups expire on their normal cycle.

10. Access, correction and complaints

You may request access to or correction of personal information we hold about you by contacting our Privacy Officer. We will respond within a reasonable period (generally 30 days) and may need to verify your identity. We may refuse access where permitted by law and will explain why.

If you have a complaint, please contact us first so we can try to resolve it. If you are not satisfied with our response, you may contact the OAIC (oaic.gov.au) in Australia or the Office of the Privacy Commissioner (privacy.org.nz) in New Zealand.

11. Limitation of liability and protection of individuals

All obligations under this Policy are obligations of CNETS PTY LTD only. To the maximum extent permitted by law, no director, officer, shareholder, owner, employee or contractor of CNETS has any personal liability under or in connection with this Policy or the handling of personal information through the Service, and any claim must be brought only against CNETS PTY LTD.

To the maximum extent permitted by law, CNETS's liability in connection with this Policy is limited as set out in the Terms of Use and Disclaimers, and CNETS is not liable for customer content, customer instructions, or the acts or omissions of customers, their users, auditors, suppliers or third-party systems they connect. Nothing in this Policy excludes rights that cannot lawfully be excluded under the Australian Consumer Law or the New Zealand Consumer Guarantees Act 1993.

12. Changes and contact

We may update this Policy from time to time. The current version is always available on this page, and material changes will be notified through the Service or by email.

Privacy Officer, CNETS PTY LTD — email: privacy@cnets.com.au.

© 2026 CNETS PTY LTD. All rights reserved.