How we collect, use and protect your personal information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
BlueArc Technologies · Last updated 25 August 2026
BlueArc Technologies Pty Ltd, ABN 61 690 034 121, builds and operates compliance software. This policy explains what personal information we collect, why we collect it, who else sees it, where it is held and how long we keep it.
It covers our website, our client portal and the systems we use to run our business. It does not describe what our clients do with their own data inside our software. Where a client uses BlueArc software to handle information about their own workers, customers or assets, that client decides how that information is handled and this policy does not govern it.
We are committed to handling personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). We apply that standard to everything we do, and we do not draw a distinction based on whether a particular obligation is legally compulsory for a business of our size.
When you make an enquiry through our website. Your name and email address, and optionally your company, the product you are interested in and your message. We also record the IP address the enquiry came from, to help us identify automated abuse.
When you use our website assistant. Your question is processed to produce an answer. If you then choose to tick the consent box and ask us to contact you, we collect your name, email address, optional company and message, along with the reference for that conversation. Section 4 explains this in detail because it involves an external service.
When you become a client. We record your business name, website, ABN, industry and address, and for each person we deal with, their name, role, email address and phone number.
When you accept a proposal. We record the full name typed into the acceptance field, the date and time of acceptance, the IP address it was accepted from, and which version of our terms applied at that moment. We do this because acceptance forms a contract and we need a reliable record of it. We do not capture a drawn or scanned signature.
When we invoice you. We record a point in time copy of the billing name, ABN and address the invoice was issued to, so that the invoice remains accurate even if your details later change.
When you use the client portal. Your email address, a securely hashed version of your password, and if you enable two factor authentication, an encrypted authentication secret. We record when you last signed in.
We do not collect payment details. We are paid by bank transfer. We do not capture, process or store credit card numbers or bank account details belonging to clients, and we do not use a payment processor.
We do not run a mailing list. We have no newsletter, no subscribe form and no marketing send capability. Every email we send is transactional, meaning it responds to something you did.
Our website has no file upload. There is nowhere on our public website for you to send us a document.
The client portal does accept files, briefly. After you become a client we ask for the things we need to set your software up, and some of those are documents. You send them by signing in to your client portal; there is still nowhere on our public website to send us a file. We accept PDF, JPG, PNG, HEIC, DOCX, XLSX, CSV and TXT files, up to 25 MB each and 100 MB for the whole request, and we refuse anything else.
We do not keep those files. They are held in temporary storage only until your completed pack reaches our team, and are deleted as soon as it does. What we keep is the written answers and the record of what was asked, because that is the business record; the documents themselves are not.
Sometimes those documents are about other people. A list of the staff who need access, or a licence or qualification record, is information about your workers rather than about you. We ask for the minimum we need, we hold it only for the days it takes to complete your setup, and it is deleted with the rest of the files. We do not use it for anything other than setting up your software.
To answer enquiries, to prepare and issue proposals, to deliver and support the software you have subscribed to, to invoice and be paid, to keep an accurate record of what was agreed and when, and to meet our record keeping obligations under Australian law.
We do not sell personal information. We do not disclose it for anyone else's marketing.
Information held in our systems, whether it is a client's operational data or a person's contact details, is not used to train any artificial intelligence model, whether ours or a third party's.
Our website includes an assistant that answers questions about what we do.
What happens to your question. Your question is screened first by our own rules. Certain questions, including anything about pricing, are answered directly by us and never leave our systems. Where a question does need a generated answer, your question text and extracts from our own published website content are sent to Amazon Bedrock, an Amazon Web Services product, which is configured to process in the Sydney region.
No identifying information travels with it. The request sent to Amazon carries the question and our own content, and nothing else. It does not carry your name, your email address, your IP address, or any identifier that would let Amazon connect the question to you.
What we store. By default we do not store the text of questions or answers at all. A conversation record is created only if you tick the consent box and ask us to contact you. That record holds the conversation reference, how many exchanges took place, whether it was passed to a person, and a link to the enquiry you submitted. It does not hold the messages themselves.
The link to you. The conversation reference on its own identifies nobody. It is generated fresh each time a page loads and is not stored on your device. It becomes connected to you only at the moment you consent to be contacted, which is the purpose of consenting.
How long we keep it. Conversation records are deleted 90 days after your last interaction, by an automated job that runs daily.
| Who | What they receive | Where |
|---|---|---|
| Amazon Web Services | Hosting for our application and database, archived copies of signed proposals and invoices, and temporary storage for onboarding documents until they are delivered and deleted | Sydney |
| Amazon Bedrock | Website assistant question text only, with no identifying information | Sydney |
| Cloudflare | Every request to this website passes through Cloudflare, which provides our security and content delivery. It sees the request, including your IP address, and runs a cookieless count of page views | Global network, see below |
| Microsoft 365 | Every email we send, which may include your name, email address, and attached proposals or invoices | See below |
| Google Analytics | Website usage and device information, only if you accept analytics cookies | See below |
We may also disclose personal information where the law requires it, or to our professional advisers where they are bound to keep it confidential.
Our application, our database and our document archive run on Australian infrastructure in the Sydney region, and our website assistant is configured to process in the same region.
Two exceptions we want to be straightforward about:
Email. We send email using Microsoft 365. Depending on the data centre region assigned to our tenancy, Microsoft may store and process that email outside Australia. Where that is the case, we rely on Microsoft's contractual commitments regarding the handling of the data it processes on our behalf.
Our security and content delivery layer. Cloudflare sits in front of this website and operates a global network, so a request from you is handled by whichever of its locations is nearest. It sees the request and your IP address in order to serve the page and to block automated abuse. It is not where your information is stored, and nothing in our database or document archive is held there.
Analytics. If you accept analytics cookies, Google may process that usage information outside Australia in accordance with its own terms.
Where personal information is handled outside Australia we take reasonable steps to ensure it is handled in a manner consistent with the Australian Privacy Principles.
Two things run before you choose anything, and we would rather say so.
Our website sits behind Cloudflare for security and speed. If Cloudflare decides your browser needs a check, it sets a cookie called cf_clearance so you are not challenged on every page. That is a security measure rather than tracking, and we cannot switch it off without switching off the protection. Cloudflare also runs a lightweight beacon that counts page views. It sets no cookies, does not identify you, does not follow you to other websites and does not build a profile of you.
Cookies we set ourselves. Two, and only if you sign in. One holds your staff session and one holds your client portal session. Both expire after 12 hours, both are marked so that scripts running in your browser cannot read them, and both are cryptographically signed. Neither is used for tracking.
Everything else needs your consent. Google Analytics does not load until you accept it. Before you choose, analytics, advertising and personalisation are all explicitly switched off, and only analytics is switched on if you accept. We do not load any advertising script, and we do not use session replay or heatmap tools.
Your choice is stored on your device, in your browser's local storage rather than in a cookie. If you want to change or withdraw it, use the choose again control on our Cookie Policy page, or clear the site data for our website in your browser settings and you will be asked again on your next visit.
Google's own cookies, if you accept analytics, are set and controlled by Google. Our Cookie Policy sets all of this out in more detail, including a table of every cookie by name.
We would rather tell you exactly what happens than make a general promise.
| What | How long |
|---|---|
| Website enquiries and the people who made them | 7 years, then automatically deleted |
| Website assistant conversation records | 90 days after the last interaction, then automatically deleted |
| Signed proposals and issued invoices | 7 years, enforced by storage that cannot be altered or deleted early |
| Documents you upload to complete your onboarding | Held only until your completed pack is delivered to our team, then deleted. Never longer than the time you are given to complete it, plus 7 days if it reaches us as a download link |
| Client records, contacts, subscriptions and billing history | For as long as you are a client, and afterwards for as long as we need them for tax, legal and record keeping purposes |
| Client portal and staff accounts | Deactivated rather than deleted, so that the history of who did what remains accurate |
| Server logs, which include IP addresses | 14 days, then rotated out |
| Our internal audit record of actions taken in our systems | Retained indefinitely, see below |
About the audit record. Our systems keep a permanent record of actions taken inside them, including who did what and when, and the IP address it came from. It cannot be edited or deleted, deliberately, because a record that can be quietly changed is not a record. As at 21 August 2026 a small number of historical entries also contain an email address. New entries no longer do. Those entries hold the same addresses already held in our client and enquiry records, and we have chosen not to break the integrity of the audit record to remove them.
Personal information is held on Australian infrastructure with encrypted storage and is not reachable directly from the internet.
Inside our business, access is limited by role. A staff member sees only the clients assigned to them and the records belonging to those clients. Only an administrator can see everything. Every change to a record, every document downloaded from our archive and every access that is refused is recorded in the audit record described above.
Passwords are stored only as one way hashes, never in a form that could be read back. Two factor authentication is available and the underlying secret is stored encrypted.
If we become aware of unauthorised access to, or disclosure or loss of, personal information we hold, we will assess it promptly and take steps to contain it.
Where we conclude that the incident is likely to result in serious harm to an affected individual, we will notify the individuals concerned and the Office of the Australian Information Commissioner as soon as practicable, consistent with the Notifiable Data Breaches scheme. Where we hold information on behalf of a client, we will also notify that client so they can meet their own obligations.
Access. You can ask us what personal information we hold about you. We will respond within 30 days and we do not charge for it.
Correction. If something we hold is wrong, tell us and we will fix it.
Deletion. You can ask us to delete personal information we hold about you. We will do so unless we are required to keep it, for example where it forms part of a financial record we must retain for seven years. Where we cannot delete it, we will tell you why, and where we can, we will remove the parts that identify you rather than keep the whole record.
Complaints. If you think we have mishandled your personal information, contact us at [email protected] and we will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
We will update this policy when what we do changes. The date at the top tells you when it was last reviewed. Where a change materially affects how we handle information we already hold about you, we will take reasonable steps to tell you rather than rely on you noticing.
BlueArc Technologies Pty Ltd
ABN 61 690 034 121
Level 35, 100 Barangaroo Avenue, Sydney NSW 2000
1300 171 099