1. Scope of This Policy
1.1 Who We Are
Empire Labs Pty Ltd (ACN 690 601 701) ("Empire Labs", "we", "us", "our") is the developer and distributor of WitnessOS, a self-hosted runtime governance platform for autonomous AI agents. Our registered office is in Townsville, Queensland, Australia.
1.2 Applicability
This Privacy Policy ("Policy") describes how we collect, hold, use, disclose, and protect Personal Information (as defined in the Privacy Act 1988 (Cth)) when you:
- Visit or interact with our website at witnessos.com.au or any related subdomains (the "Website");
- Purchase, evaluate, or obtain a license to use WitnessOS (the "Software");
- Create or manage an account with us (an "Account");
- Communicate with us for support, inquiries, or other purposes; or
- Otherwise interact with our business in any manner (collectively, the "Services").
1.3 Commitment
We are committed to protecting the privacy of your Personal Information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) set out in Schedule 1 thereof, and all other applicable privacy and data protection laws, including (where applicable) the General Data Protection Regulation (GDPR) (EU) 2016/679 and the California Consumer Privacy Act (CCPA) Cal. Civ. Code §1798.100 et seq., as amended by the California Privacy Rights Act (CPRA).
1.4 Defined Terms
Capitalised terms used but not defined in this Policy have the meanings given to them in our Terms of Service, including but not limited to "Licensee Data" (being all data generated, collected, stored, or processed by your instance of the Software) and "Software".
2. What This Policy Does Not Cover
2.1 Self-Hosted Software
The Software is self-hosted and is deployed on infrastructure owned, leased, or otherwise controlled by you. Except as expressly provided in Section 4.5 of this Policy and Section 7.1 of our Terms of Service (Phone-Home and Integrity Reporting), we do not and cannot access, view, store, process, or transmit any Licensee Data. This includes, without limitation:
- Agent action logs, event histories, or runtime outputs;
- Audit trail entries, hash chains, or cryptographic proofs generated by the Software;
- Policy configurations, rules, or governance parameters;
- Any data, records, or files processed, analysed, or generated by agents being governed by the Software;
- System logs, performance metrics, or error reports generated by your instance;
- Any derivative or aggregate data derived from any of the foregoing.
2.2 Your Responsibilities
You are the data controller (as defined in applicable privacy law) for all Licensee Data processed through your instance of the Software. Accordingly, you bear all responsibility and liability under applicable privacy and data protection laws for such Licensee Data, including but not limited to:
- Providing appropriate privacy notices and obtaining any necessary consents;
- Responding to access, correction, erasure, portability, and other data subject rights requests;
- Notifying relevant authorities and affected individuals of any data breaches involving Licensee Data;
- Ensuring that appropriate technical and organisational measures are in place to protect Licensee Data;
- Complying with any applicable cross-border data transfer restrictions.
Our Terms of Service (Sections 9, 10, and 11) further provide that we accept no liability whatsoever for your handling of Licensee Data, and you agree to indemnify us against any claims arising therefrom.
2.3 Third-Party Services
The Software may include features that enable integration with third-party services, platforms, or APIs. Any data you choose to transmit to such third-party services through the Software is governed by the privacy policies of those third parties, not this Policy. We are not responsible for the privacy practices of any third-party service you connect to the Software.
3. Personal Information We Collect
Because we do not host your instance of the Software, the Personal Information we collect is strictly limited to what you provide to us directly, or what is generated through your interactions with our Website, Account, and Services.
3.1 Information You Provide to Us
3.1.1 Account and License Information
- Identity Information: Your full name, corporate or organisation name, job title, business address, and telephone number.
- Contact Information: Your email address (which we use as your primary Account identifier).
- Authentication Information: A hashed and salted password (or third-party OAuth or SSO identifier), session tokens, and audit logs of your login activity on our Account systems.
- License Information: License Key identifiers, authorised machine fingerprints, Software version history, license tier, and license term dates.
- Communication Preferences: Your preferences regarding product updates, marketing communications, and notification channels.
3.1.2 Payment Information
- Billing name, billing address, and any applicable tax identification numbers (e.g., ABN, VAT ID).
- Payment method details (credit or debit card type, last four digits, expiration date), which are collected and processed directly by our third-party payment processor (currently Stripe, Inc.). We do not store full credit or debit card numbers, CVV codes, or similar sensitive payment data on our systems.
- Invoice history, transaction records, and payment receipts.
3.1.3 Support and Communications
- The content and metadata of all emails, support tickets, forum posts, chat messages, and other communications you send to us.
- Records of telephone calls (if applicable), including call recordings where required for quality assurance or regulatory compliance.
- Any files, screenshots, system logs, or other materials you voluntarily provide to us in connection with a support request.
3.2 Information Collected Automatically
3.2.1 Website Analytics
- Internet Protocol (IP) address, which may be used to infer approximate geographic location at the city or regional level;
- Browser type and version, operating system, device type and model, screen resolution, and language preferences;
- Referring URL, pages visited on our Website, time and date of visits, time spent on each page, clickstream data, and download activity;
- Interaction data, such as button clicks, form interactions (without capturing submitted form content), and scroll depth.
3.2.2 Phone-Home and Integrity Reporting
- As described in Section 7.1 of our Terms of Service, the Software may periodically communicate with our servers solely to transmit: (a) License Key identifier and machine fingerprint; (b) integrity verification result (pass/fail) and file count; (c) Software version and platform information; and (d) a unique environment identifier. These communications do not include any Licensee Data.
3.3 Information We Do Not Collect
For the avoidance of doubt, we do not collect, and we design our systems to avoid collecting:
- Trading, transaction, or financial data processed through the Software;
- Personal information of your customers, end users, or employees from or through your instance of the Software;
- Sensitive information (as defined in APP 3 of the Privacy Act 1988 (Cth)), such as health information, biometric data, or political opinions;
- Children's personal information (we do not knowingly collect Personal Information from individuals under the age of 18);
- Precise geolocation data from your device or your instance of the Software.
4. How We Use Your Personal Information
We use your Personal Information only for the purposes described in this Policy or as otherwise disclosed to you at the time of collection. Our primary purposes are:
4.1 License Management and Account Administration
To issue, activate, verify, and manage License Keys; to create and maintain your Account; to verify your identity; to communicate with you regarding your license status, renewals, and Account activity; and to enforce compliance with our Terms of Service.
4.2 Billing and Payment Processing
To process payments, generate invoices, manage subscriptions, handle refunds, and maintain financial records in compliance with applicable tax and record-keeping laws, including the Taxation Administration Act 1953 (Cth).
4.3 Customer Support
To respond to your inquiries, troubleshoot technical issues, provide product support, and communicate with you about the resolution of support requests.
4.4 Product Improvement and Analytics
To analyse Website usage trends, diagnose technical issues, improve the functionality and user experience of the Website and Services, and develop new features and products. Analytics are conducted on an aggregated, de-identified basis wherever possible.
4.5 Security and Integrity
To monitor and verify the security and integrity of the Software (including through Phone-Home communications as described in Section 3.2.2 of this Policy and Section 7.1 of the Terms of Service); to detect and prevent unauthorised use, tampering, or distribution; to enforce compliance with our Terms of Service; and to protect our rights, property, and safety, and the rights, property, and safety of our customers and others.
4.6 Legal and Regulatory Compliance
To comply with all applicable laws, regulations, court orders, subpoenas, and other legal processes; to respond to requests from regulators; and to establish, exercise, or defend legal claims.
4.7 Communications
To send you service-related communications, including license renewal notices, security alerts, product update notifications, and changes to our terms, conditions, and policies. We may also send you marketing communications about our products and services, but only where you have provided your express consent (opt-in) to receive such communications. You may withdraw your marketing consent at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at contact@empirelabs.com.au.
5. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, our processing of your Personal Information is based on the following legal bases under the GDPR:
- Performance of a Contract (Article 6(1)(b)): Processing necessary to deliver the Services to you, including license management, Account administration, billing, and support.
- Legitimate Interests (Article 6(1)(f)): Processing necessary for our legitimate interests, including product improvement and analytics, security monitoring, fraud prevention, enforcement of our Terms of Service, and direct marketing (where you have not objected). We balance these interests against your privacy rights and do not process where your interests override ours.
- Compliance with a Legal Obligation (Article 6(1)(c)): Processing necessary to comply with our legal obligations, including tax and record-keeping requirements and responses to legal process.
- Consent (Article 6(1)(a)): Processing for marketing communications where we have obtained your express consent. You have the right to withdraw your consent at any time.
6. Data Sharing and Disclosure
6.1 No Sale of Personal Information
We do not and will not sell, rent, trade, or otherwise transfer your Personal Information to third parties for monetary or other valuable consideration, including as "sale" is defined under the CCPA/CPRA, the GDPR, or any other applicable law.
6.2 Service Providers (Data Processors)
We engage trusted third-party service providers who process Personal Information on our behalf solely for the purposes described in this Policy. These providers are contractually bound by Data Processing Agreements (DPAs) that prohibit them from using your Personal Information for any purpose other than providing the contracted services, and that require them to maintain security standards equivalent to our own. Our current categories of service providers include:
- Payment Processing: Stripe, Inc. - processes payment card transactions (we do not store full card numbers).
- Email Communications: our email service provider - sends transactional emails (license keys, invoices, support responses) and, where opted in, marketing communications.
- Website Hosting: our web hosting provider - hosts our Website and Account portal.
- Analytics: our analytics provider - processes aggregated, de-identified Website usage data.
A current list of our sub-processors, together with their locations and processing activities, is available on request by emailing contact@empirelabs.com.au. We will provide at least thirty (30) days' prior notice of any changes to our sub-processors.
6.3 Legal Requirements
We may disclose your Personal Information if we are required to do so by law, regulation, or legal process (including but not limited to a court order, subpoena, warrant, or regulatory demand). We will, where permitted by law, use reasonable efforts to notify you in advance of such disclosure to allow you to seek a protective order or other appropriate relief.
6.4 Business Transactions
In the event of a merger, acquisition, divestiture, restructuring, reorganisation, dissolution, or sale of all or substantially all of our assets, your Personal Information may be transferred as part of that transaction. We will provide you with prior written notice (via email and a prominent notice on our Website) of any such change in ownership or control of your Personal Information, and you will be given an opportunity to opt out of any material change in the use of your information resulting from such transaction.
6.5 Protection of Rights
We may disclose your Personal Information where reasonably necessary to establish, exercise, or defend our legal rights, to protect against fraud or other illegal activity, or to protect the rights, property, or personal safety of Empire Labs, our customers, or the public.
7. Cross-Border Data Transfers
7.1 Data Storage
Our primary business systems and data storage are located in Australia. We and our service providers may store and process your Personal Information in Australia, the United States, and other jurisdictions where our service providers operate.
7.2 Adequacy Safeguards
Where Personal Information is transferred to a jurisdiction that has not been determined by the European Commission or the UK Government (as applicable) to provide an adequate level of data protection, we will implement appropriate safeguards to protect your Personal Information, including but not limited to:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission under Article 46(2) of the GDPR and/or the UK International Data Transfer Agreement (IDTA);
- Data Processing Agreements that incorporate equivalent protections.
By providing your Personal Information to us, you acknowledge that we may transfer, store, and process your information in accordance with this Section 7.
7.3 APP Compliance
For the purposes of Australian Privacy Principle 8 (Cross-border disclosure of personal information), we will take such steps as are reasonable in the circumstances to ensure that any overseas recipient of your Personal Information does not breach the APPs. However, by providing your Personal Information, you consent to the disclosure of your information to overseas recipients as described in this Section 7, with the understanding that such recipients will not be subject to the APPs and that you may not be able to seek redress under the Privacy Act 1988 (Cth) for any mishandling by such recipients.
8. Data Retention
We retain your Personal Information only for as long as reasonably necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our retention periods are as follows:
- Account and License Data: Retained for the duration of your Account or license term, plus a period of thirty (30) calendar days after termination of your Account or license, after which it is securely and permanently deleted, except that:
- Billing and Transaction Records: Retained for a period of seven (7) years after the end of the financial year in which the transaction occurred, to comply with our obligations under the Taxation Administration Act 1953 (Cth) and the Corporations Act 2001 (Cth).
- Support Communications: Retained for a period of twelve (12) months after the resolution of the applicable support request or the last communication in a series, after which they are securely deleted, provided that we may retain records of systemic issues or feature requests on an anonymised basis for product improvement purposes.
- Phone-Home and Integrity Records: Retained for a period of twelve (12) months after receipt, after which they are securely deleted, provided that aggregated statistics (e.g., number of active instances, integrity pass/fail rates) may be retained indefinitely on an anonymised basis.
- Website Analytics: Retained in aggregated, de-identified form indefinitely. Raw logs containing IP addresses are deleted after ninety (90) calendar days.
- Marketing Communications Data: Retained until you opt out or withdraw consent, or until thirty (30) calendar days after termination of your Account, whichever is earlier.
9. Data Security
We implement and maintain industry-standard technical and organisational security measures to protect your Personal Information against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption at Rest: All stored Personal Information is encrypted using AES-256 or equivalent industry-standard encryption algorithms.
- Encryption in Transit: All communications with our systems are encrypted using TLS 1.3 (or higher) protocol.
- Access Controls: Access to Personal Information is restricted to authorised personnel on a strict need-to-know basis, enforced through role-based access controls (RBAC), multi-factor authentication (MFA), and individual accountability.
- Audit Logging: All access to and operations on Personal Information are logged and subject to periodic review. Logs are retained for a minimum of twelve (12) months.
- Incident Response: We maintain a documented security incident response plan and conduct periodic tabletop exercises and penetration testing.
- Third-Party Audits: We conduct regular security assessments of our infrastructure, including vulnerability scanning and, where appropriate, independent penetration testing.
10. Data Breach Notification
10.1 NDB Scheme (Australia)
In accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth), if we reasonably believe that a data breach has occurred involving your Personal Information that is likely to result in serious harm, we will:
- Conduct a reasonable and expeditious assessment of the suspected breach (as required by s 26GL of the Act);
- Notify you as soon as practicable after forming the relevant belief (s 26WH);
- Provide recommendations to mitigate any potential harm; and
- Notify the Office of the Australian Information Commissioner (OAIC) in accordance with s 26WB of the Act.
10.2 GDPR/EU Breach Notification
If we are subject to the GDPR in respect of your Personal Information, we will notify the relevant supervisory authority of any breach without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. We will notify you directly where required by Article 34 of the GDPR.
10.3 Scope Limitation
The obligations in this Section 10 apply solely to breaches of our own systems and the Personal Information we hold. They do not apply to any breach of your self-hosted instance of the Software or any Licensee Data processed through the Software, which remains your sole responsibility as the data controller.
11. Your Rights
11.1 Australian Privacy Rights (APPs)
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the following rights in respect of your Personal Information held by us:
- Right of Access (APP 12): You have the right to request access to the Personal Information we hold about you. We will respond to your request within a reasonable period (not exceeding thirty (30) calendar days) and provide access in the manner requested unless it is impracticable or unreasonable to do so. A reasonable fee may apply for the retrieval and supply of information.
- Right of Correction (APP 13): You have the right to request correction of any Personal Information we hold about you that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will take reasonable steps to correct the information and, where applicable, notify any third parties to whom we have disclosed the incorrect information.
- Right to Complain: You have the right to lodge a complaint regarding our handling of your Personal Information (see Section 13).
11.2 Additional Rights (GDPR - EEA/UK)
If you are located in the European Economic Area or the United Kingdom, you may have the following additional rights under the GDPR:
- Right to Erasure (Article 17): The right to request deletion of your Personal Information where it is no longer necessary for the purposes for which it was collected, where you withdraw consent, where you object to processing, or where processing is unlawful.
- Right to Data Portability (Article 20): The right to receive your Personal Information in a structured, commonly used, machine-readable format and to transmit that information to another controller.
- Right to Restriction of Processing (Article 18): The right to request restriction of processing where you contest the accuracy of the data, where processing is unlawful, or where you have objected to processing pending verification of legitimate grounds.
- Right to Object (Article 21): The right to object to processing of your Personal Information based on our legitimate interests, including profiling and direct marketing.
- Right to Withdraw Consent: The right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
11.3 California Privacy Rights (CCPA/CPRA)
If you are a resident of the State of California, the CCPA/CPRA grants you the following additional rights:
- Right to Know: The right to request disclosure of the categories and specific pieces of Personal Information we have collected about you, the categories of sources from which it was collected, the business purpose for collecting it, and the categories of third parties with whom it was shared.
- Right to Delete: The right to request deletion of Personal Information we have collected about you, subject to certain exceptions.
- Right to Opt Out of Sale: As we do not sell Personal Information, there is no opt-out mechanism required. However, we will not sell your Personal Information in the future without providing you with notice and an opportunity to opt out.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
11.4 Exercising Your Rights
To exercise any of the rights described in this Section 11, please submit your request to:
- Email: contact@empirelabs.com.au with the subject line "Privacy Request"
- Mail: Empire Labs Pty Ltd, Townsville, Queensland, Australia
We will verify your identity before processing your request and may require additional information to confirm your identity. We will respond to your request within the timeframe required by applicable law (generally thirty (30) calendar days under Australian law, and within one (1) month under the GDPR, extendable by up to two (2) additional months for complex requests).
12. Cookies and Website Tracking
12.1 Our Use of Cookies
Our Website uses only strictly necessary cookies required for the basic operation and security of the Website. We do not use cookies for advertising, cross-site tracking, behavioural profiling, or analytics that identify individual visitors. The types of cookies we use are:
- Essential Session Cookies: Required for the operation of the Website, including maintaining session state and enabling secure login to Account portals. These cookies are deleted when you close your browser.
- Preference Cookies: Store your theme preference (e.g., dark mode) and other non-identifiable user preferences. These cookies persist for up to twelve (12) months.
- Security Cookies: Used to detect and prevent fraudulent or abusive access to our systems.
12.2 Third-Party Cookies
We do not permit third-party advertising networks, social media platforms, or analytics providers to set cookies on our Website that track your activity across other websites or services. Any third-party cookies used on our Website are limited to those required for the functionality of embedded content (e.g., video players), and such third parties are restricted by contract from using such cookies for any purpose other than providing the embedded service.
12.3 Cookie Controls
You can control and manage cookies through your browser settings. Most browsers allow you to block or delete cookies, or to receive a warning before a cookie is stored. Please note that disabling essential cookies may affect the functionality of our Website.
13. Complaints and Dispute Resolution
13.1 Internal Complaint Process
If you believe that we have breached the Privacy Act 1988 (Cth) or any other applicable privacy law, or that we have otherwise mishandled your Personal Information, please contact us with full details of your concern:
- Email: contact@empirelabs.com.au with the subject line "Privacy Complaint"
- Mail: Empire Labs Pty Ltd, Attn: Privacy Officer, Townsville, Queensland, Australia
We will acknowledge receipt of your complaint within five (5) business days and will investigate and respond in writing within thirty (30) calendar days, setting out our findings and any remedial action taken or proposed.
13.2 External Dispute Resolution
If you are not satisfied with our response to your complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992 (within Australia)
- Mail: GPO Box 5218, Sydney NSW 2001, Australia
13.3 GDPR Supervisory Authority
If you are located in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority (for EEA residents) or the Information Commissioner's Office (for UK residents).
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, legal requirements, or industry standards. Material changes will be communicated as follows:
- We will notify you via email to the address associated with your Account at least fourteen (14) calendar days before the effective date of any material change.
- We will post a notice on our Website at least fourteen (14) calendar days before the effective date of any material change.
- The "Last updated" date at the top of this Policy will reflect the date of the most recent revision.
Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree to a material change, your sole remedy is to close your Account and cease using the Services before the effective date of such change.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, our data handling practices, or your privacy rights, please contact our Privacy Officer:
- Email: contact@empirelabs.com.au
- Mail: Empire Labs Pty Ltd, Attn: Privacy Officer, Townsville, Queensland, Australia
We welcome your inquiries and will respond to all legitimate requests within the timeframe required by applicable law.
Privacy Policy - Version 2.1 - Effective 5 July 2026
Patent pending AU 2026906017. © 2026 Empire Labs Pty Ltd. All rights reserved.