Privacy & Data Use Statement

At ValiDATA, safeguarding your information is core to our mission. We want you to understand exactly what we collect, why we collect it, and how we protect it while you use the AI Readiness Navigator ("the Platform"). If anything is unclear, please get in touch – you always have the final say over your data.


What we collect

Email address only – your email address for passwordless authentication and report delivery. We do not collect or store passwords.
Assessment responses (session-based) – your ratings and comments during active assessment sessions, temporarily stored to generate your personalised report. This data is automatically cleared when you complete or abandon your assessment.
Payment records – when you purchase Standard or Premium assessments, we store payment transaction details (amount, date, Stripe payment ID) but not your credit card information.
Generated reports – completed assessment reports are temporarily cached for up to 24 hours to enable immediate viewing and email delivery, then automatically deleted.
Usage analytics – aggregated, anonymised metrics (page views, assessment completion rates, device types) to improve platform performance.
Security logs – IP addresses, timestamps, and access patterns for fraud prevention, rate limiting, and platform security.

How we store your data

Primary database – your email, assessment completion count, and payment records are stored securely in our encrypted database.
Temporary storage – authentication tokens (30-minute expiry), active assessment sessions, and report cache are stored temporarily and automatically deleted.
No persistent assessment data – your individual assessment responses are never permanently stored. They exist only during your active session to generate your report.
Email tokens – passwordless authentication links expire after 30 minutes and are immediately invalidated after use.

Why we collect it

  1. Passwordless authentication – to securely verify your identity without requiring password management.
  2. Assessment delivery – to generate and display your personalised AI maturity report in real-time.
  3. Payment processing – to enable access to Standard and Premium assessment tiers (one payment per assessment).
  4. Report delivery – to email your completed assessment report as a formatted document.
  5. Platform security – to prevent abuse, detect suspicious activity, and maintain service availability.
  6. Service improvement – to analyse usage patterns and enhance the assessment experience.

We never sell personal information, nor do we use your data for third-party advertising or marketing.

Data retention & deletion

Assessment responses – deleted immediately after report generation (typically within 1 hour)
Authentication tokens – expire and are deleted within 30 minutes of creation
Report cache – automatically deleted after 24 hours
Email & payment records – retained until you request deletion or delete your account
Security logs – retained for up to 12 months for audit and security purposes
Usage analytics – anonymised data retained indefinitely for service improvement

Payment & assessment model

One payment per assessment – each Standard or Premium assessment requires a separate payment
No subscription – you only pay for individual assessments you choose to complete
Payment data – we store transaction records but never your credit card details (handled securely by Stripe)
Assessment data – your responses are not tied to payment records and are deleted after report generation

Storage & security

Our platform operates on enterprise-grade cloud infrastructure with:

Encryption in transit – all data transmission protected by TLS 1.2+ encryption
Encryption at rest – database and temporary storage encrypted with industry-standard protocols
Access controls – strict least-privilege access policies for authorised personnel only
Regular backups – automated, encrypted backups of essential data (email addresses and payment records only)
Security monitoring – continuous monitoring for unauthorised access attempts and suspicious activity

Your rights

Under Australian Privacy Principles (APPs) and comparable global regulations you may:

Access your personal information (email address and payment history)
Correct any inaccurate personal information we hold
Delete your account and associated data (assessment responses are already automatically deleted)
Object to processing for specific purposes
Withdraw consent at any time
Lodge a complaint with the OAIC if you feel your rights have not been respected

Cookies & tracking

We use minimal cookies for essential functionality:

Session cookie – to maintain your authenticated session during assessment completion
Authentication token – temporary token for passwordless login (30-minute expiry)
No advertising trackers – we do not use third-party advertising or marketing cookies
No persistent tracking – cookies are cleared when you log out or your session expires

Third-party services

We use the following trusted third-party services:

Stripe – secure payment processing (they handle all credit card data, not us)
OpenAI – AI-powered report generation (assessment responses sent temporarily for analysis, not stored by OpenAI)
Cloud hosting – enterprise-grade hosting infrastructure with ISO 27001 certification
Email delivery – Microsoft Graph API for secure report delivery to your email address

Data sharing

We do not sell, rent, or share your personal information except:

Payment processing – transaction data shared with Stripe for payment completion
Report generation – anonymised assessment data sent to OpenAI for AI analysis (no personal identifiers included)
Legal requirements – if required by law, court order, or to protect our legal rights

Changes to this statement

We'll post any material updates to this policy on the Platform and may notify you via email for significant changes. Continued use of the Platform after updates constitutes acceptance of the revised terms.


Questions or data requests? Email us at info@validata.ai – we're committed to transparency and protecting your privacy.

Last updated: June 2025