Privacy Policy · Effective Risk Management

Privacy Policy.

Draft · Pending review
This is a draft pending legal review. The content reflects MaturityOne's actual operational and security commitments as published on the Trust & Security page, but is not yet a final or legally-binding document. Specific clauses requiring counsel input are marked inline.
- Last updated27 April 2026
- EffectivePending review
- VersionDraft 0.1
- EntityEffective Risk Management Pty Ltd
- Section 01

Who we are

MaturityOne is a maturity assessment platform operated by Effective Risk Management Pty Ltd, an Australian-incorporated company headquartered in Melbourne. Legal review required Australian Business Number and registered address details to be inserted by counsel.

This Privacy Policy describes how we collect, use, share and protect personal information across the MaturityOne platform and associated websites. It applies to customer users, prospective customers, website visitors, and security researchers who interact with us.

For the purposes of the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), Effective Risk Management Pty Ltd is the entity responsible for personal information collected through MaturityOne. For the purposes of the EU General Data Protection Regulation (GDPR), we act as a processor in respect of personal information that customers upload to the platform, and as a controller in respect of information collected directly from website visitors and prospective customers.

- Section 02

Personal information we collect

We collect personal information in three categories:

Account and identity information

When a user is provisioned into a MaturityOne customer tenant, we collect: name, work email address, role within the customer organisation, organisation name, country, and authentication identifiers (typically managed via the customer's SSO provider - Okta, Microsoft Entra ID, Google Workspace, or equivalent).

Platform usage information

We collect information about how users interact with the platform - assessments completed, scores recorded, evidence uploaded, comments and decisions logged. This information is purpose-limited to product operation, security, and customer support.

Website visitor and contact form information

When you submit the contact form on this website, we collect the information you provide: name, work email, role, organisation, country, sector, journey stage, and the content of your message. We use this information solely to prepare and conduct the conversation you have requested.

We do not collect sensitive information (as defined under the Privacy Act 1988) unless explicitly required for a specific purpose, with consent. Legal review required The exhaustive list of personal information categories - particularly any biometric, health, or financial identifiers - must be confirmed by counsel before publication.

- Section 03

How we use personal information

We use personal information for the following purposes only:

  • Platform operation. To deliver MaturityOne to the customer organisation, including assessment workflows, cross-domain cascade calculations, program management, reporting, and audit logging.
  • Customer support. To respond to support requests, troubleshoot issues, and communicate with users about service-impacting events.
  • Security. To detect, investigate and respond to security incidents, fraud, and unauthorised access attempts.
  • Aggregate benchmarking. Where customers explicitly opt in, fully-anonymised and aggregated benchmarking statistics are produced. Individual customer data is never identifiable in benchmarking output.
  • Sales and prospect engagement. Where you have submitted a contact form, we use the information to prepare for the conversation, conduct the conversation, and provide a written recommendation. We do not run automated sales sequences and we do not share contact form data with third parties.
  • Legal and regulatory compliance. Where required by law, regulator request, or court order.

What we do not do

We do not sell personal information. We do not licence personal information to third parties. We do not use customer data to train third-party AI models. We do not serve advertisements through the platform. We do not deploy third-party advertising trackers, behavioural analytics pixels, or retargeting cookies on this website.

- Section 04

Sharing and disclosure

We share personal information only in the following limited circumstances:

  • With sub-processors who provide infrastructure, security, and operational services to MaturityOne, under written Data Processing Agreements. See Section 06.
  • Within the customer's tenant - users in a customer tenant can see information shared by other users in the same tenant, subject to role-based access controls administered by the customer.
  • With professional advisors (legal, audit, accountancy) under confidentiality obligations, where reasonably necessary.
  • Where required by law - including in response to lawful regulator requests, court orders, or legal process. Legal review required Specific protocols for handling government and law-enforcement requests must be confirmed by counsel.
  • In connection with a business transaction - if Effective Risk Management Pty Ltd is involved in a merger, acquisition, restructure, or asset sale, personal information may be transferred to the acquiring entity, subject to equivalent protection commitments. Legal review required Successor entity language to be confirmed.
- Section 05

Data residency and storage

Customer data is stored in Google Cloud Platform Australia, with the primary region in Sydney (australia-southeast1) and disaster recovery in Melbourne (australia-southeast2).

Data residency is a contract-level commitment. Customer data - primary, backup, analytics, and logs - does not leave the Australian region. Additional Asia-Pacific and GCC regions (New Zealand, Hong Kong, UAE, Saudi Arabia) are on the platform roadmap as customer demand and regulatory drivers warrant; expansion will be subject to prior customer notification.

Backups are retained for 35 days on a rolling basis with point-in-time recovery enabled. Recovery objectives: RTO 4 hours, RPO 15 minutes.

Data in transit is encrypted using TLS 1.3 only; older versions are blocked at the load balancer. Data at rest is encrypted using AES-256, with Google-managed encryption keys by default and Customer-Managed Encryption Keys (CMEK) available on the Enterprise tier.

- Section 06

Sub-processors

Our primary infrastructure sub-processor is:

  • Google Cloud Platform - primary cloud infrastructure (compute, storage, databases, networking). Australian regions only. Data Processing Agreement in place.

Additional sub-processors (transactional email, monitoring, customer support tooling, etc.) are disclosed in our trust pack under non-disclosure agreement on request from active customers and verified prospects in evaluation. The complete list is updated whenever a sub-processor is added, removed, or changes region.

Every sub-processor undergoes security review before onboarding and has a signed Data Processing Agreement covering data handling, residency, security, and breach notification obligations. Legal review required Customer notification protocols for sub-processor changes must be confirmed by counsel.

- Section 07

Security

We maintain a security program designed to protect personal information against unauthorised access, use, modification, disclosure, loss and destruction. Key controls include:

  • Authentication. Single Sign-On via SAML 2.0 and OIDC; MFA enforceable at tenant level; password policy defaults exceeding NIST SP 800-63B.
  • Encryption. AES-256 at rest, TLS 1.3 in transit.
  • Access control. Granular role-based access (Admin, Assessor, Reviewer, Executive); least-privilege by default; every permission change audit-logged.
  • Audit logging. Every user action, data change, and permission modification logged to a write-once audit store; retained for seven years; tamper-evident and cryptographically signed.
  • Personnel. Police checks, reference verification, and confidentiality undertakings for all personnel with production access; quarterly access reviews.
  • Incident response. Documented plan aligned to NIST SP 800-61; severity-based service levels for customer notification - 72-hour maximum for any security incident affecting customer data.

Our compliance program is detailed on the Trust & Security page.

- Section 08

Retention and deletion

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including legal and regulatory retention obligations.

Customer data on the platform

While a customer tenant is active, customer data is retained for the duration of the engagement.

On contract termination

On termination of a customer contract, we provide a full export of customer data in standard formats (JSON, CSV, XLSX, PDF) within 30 days. Customer data is then deleted from production systems within 60 days of contract termination, with backups expiring on the 35-day rolling backup cycle.

Audit logs

Audit logs are retained for seven years by default to support compliance, security investigation, and customer assurance obligations. Customers may request shorter retention windows where regulatory context permits.

Contact form information

Information submitted via the contact form is retained for the duration of the prospect engagement. Legal review required Specific retention periods for sales-stage contact information must be confirmed by counsel.

- Section 09

Your rights

Depending on the jurisdiction in which you reside, you may have the following rights in respect of your personal information:

  • Right to access - request a copy of the personal information we hold about you.
  • Right to rectification - request correction of inaccurate or incomplete personal information.
  • Right to erasure - request deletion of your personal information, subject to legal and contractual retention obligations.
  • Right to restrict processing - request that we limit how we use your personal information.
  • Right to data portability - receive your personal information in a structured, machine-readable format.
  • Right to object - object to certain processing activities, including direct marketing.
  • Right to withdraw consent - withdraw any consent you have given to processing.
  • Right to lodge a complaint - with the Office of the Australian Information Commissioner (OAIC) or your local data protection authority.

To exercise any of these rights, contact us at contact@effectiverm.com with the subject line "Privacy". We will respond within 30 days in accordance with the Australian Privacy Principles, and within shorter statutory timeframes where applicable in other jurisdictions.

Legal review required Jurisdiction-specific rights and procedures (GDPR, NZ Privacy Act, Hong Kong PDPO, UAE PDPL, Saudi PDPL, Pakistan PECA) must be confirmed by counsel before publication.

- Section 10

International transfers

Customer data is held in Australia as a contract-level commitment. We do not transfer customer data outside Australia in the ordinary course of operations.

Limited exceptions apply for: customer support access (offshore support is not the default - it is a per-ticket exception requiring written customer approval, logged and reviewable); and certain administrative communications conducted via international email and conferencing services.

Where international transfer of personal information is necessary, we rely on appropriate safeguards including Standard Contractual Clauses (for transfers from the European Economic Area), adequacy decisions where applicable, and equivalent measures for other jurisdictions. Legal review required Specific transfer mechanisms and contracting arrangements must be confirmed by counsel.

- Section 11

Cookies and tracking

Our website uses minimal first-party cookies necessary for site operation and security. We do not deploy third-party advertising trackers, behavioural analytics pixels, retargeting cookies, or session-replay tools.

Full details - including cookie names, purposes, retention periods, and instructions for managing cookie preferences - are set out in our Cookie Policy.

- Section 12

Children

MaturityOne is a business-to-business enterprise platform. The platform and this website are not directed to children under 16, and we do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will delete that information promptly.

- Section 13

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified to active customers in writing at least 30 days in advance, and posted to this page with an updated "Last updated" and "Effective" date.

The current version is shown in the metadata at the top of this page. Previous versions are available on request to active customers and verified prospects in evaluation.

Legal review required Notification mechanisms and customer-acceptance procedures for material changes must be confirmed by counsel.

- Section 14

Contact

For privacy questions, requests, or complaints:

  • Email: contact@effectiverm.com with subject line "Privacy"
  • Postal: Effective Risk Management Pty Ltd, Melbourne, Australia. Legal review required Full registered address to be inserted by counsel.
  • Response timeframe: Within one Australian business day for acknowledgement; within 30 days for substantive response in accordance with the Australian Privacy Principles.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or with your local data protection authority.