Detekta elects to be treated as an "organisation" under section 6EA of the Privacy Act 1988 (Cth) and complies with the Australian Privacy Principles (APPs).
This Privacy Policy explains how Risk Lab Innovation Pty Ltd (ACN: 695 286 287) trading as Detekta ("Detekta", "we", "us", "our") collects, uses, discloses, and protects personal information when you use our website and services (the "Services").
Detekta elects to be treated as an "organisation" under section 6EA of the Privacy Act 1988 (Cth) and complies with the Australian Privacy Principles (APPs). This policy has been developed in accordance with the Privacy Act and the APPs. Where users are located in other jurisdictions, we also apply the additional protections described in this policy (see Section 5 for UK/EU users).
Contact: contact@detekta.ai
This policy applies to:
Detekta provides a business platform for merchant risk assessment, transaction monitoring, investigations, and chargeback tracking. Our customers typically upload data about their merchants and transactions. In many cases, Detekta acts as a service provider / processor on the customer's instructions, and the customer is the controller of that data.
Detekta is designed to minimise personal information.
If you upload datasets that include personal information (for example, names, emails, phone numbers, addresses, identification numbers), Detekta may:
Important: Depending on your configuration and the data you provide, Detekta may still process personal information temporarily during ingestion and tokenisation. We aim not to persist raw personal information where tokenisation is enabled, but you control what data you upload.
We may collect the following categories:
A. Account and contact data
B. Billing data
C. Usage and technical data
D. Customer Data uploaded to the platform
This may include merchant and transaction information. Depending on what you upload, it may include personal information relating to individuals (e.g., sole traders, directors, payers/payees, or contact persons).
We use personal information to:
If UK/EU data protection laws apply (e.g., GDPR/UK GDPR), we rely on:
We may disclose personal information to:
A. Subprocessors and service providers
Including providers used to host and operate Detekta, such as:
B. Legal and compliance
We may disclose information if required by law, court order, regulator request, or to protect rights and safety.
C. Business transfers
If we undergo a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.
Detekta's backend database is hosted via Supabase on AWS infrastructure. Unless otherwise agreed in writing, Customer Data (including any personal information within it) is stored in a single region, typically United States (AWS us-east-1).
That means personal information may be disclosed to and stored in the United States, and may also be accessed from other locations where our service providers operate.
Where applicable, we take reasonable steps to ensure cross-border transfers are protected (e.g., contractual safeguards with providers). However, different countries may have different data protection standards.
We retain personal information only as long as necessary for the purposes described in this policy, including:
Customer Data: After cancellation/termination, we generally allow a period (typically up to 30 days) for export, then delete or de-identify Customer Data in accordance with our retention practices, unless we must retain it for legal/security reasons.
We use reasonable technical and organisational measures to protect personal information, including:
No system is perfectly secure. You are responsible for securing your user credentials and ensuring Authorised Users follow your internal security practices.
If you upload personal information to Detekta, you are responsible for:
We may use cookies and similar technologies on our website for functionality, security, and analytics. You can control cookies through your browser settings and (where implemented) our cookie banner/preferences.
Depending on your location, you may have rights to:
If Detekta is processing personal information on behalf of a customer (as processor), requests may need to be handled by the customer as controller. We will assist the customer where required.
If you have a concern or complaint about how we have handled your personal and/or sensitive information, you may make a complaint by contacting us at contact@detekta.ai.
Please include sufficient detail about the complaint, including:
We may ask you to provide further information in order to investigate your complaint.
We will acknowledge your complaint and seek to investigate and respond within a reasonable period, typically within 30 days.
If you are dissatisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC). If you are located outside Australia, you may also be able to lodge a complaint with the data protection authority in your jurisdiction.
We may send product updates or marketing where permitted by law. You can opt out using the unsubscribe link in emails or by contacting us.
The Services are not directed to children and we do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. If changes are material, we will provide notice (e.g., email or in-product notification). Continued use after the effective date means you accept the updated policy.
For privacy requests or questions:
Email: contact@detekta.ai
See also our Terms of Service.