Privacy, cookies & legal

Your data. Your choices. Clear terms.

This page explains how Nullify handles personal information, how optional website technologies work, and how to exercise your privacy rights. Product-specific contractual terms and data-processing documents are also available below.

Effective: 26 July 2026 · Last updated: 26 July 2026

Privacy notice

Controller: Nullify Holdings Pty Ltd (ABN 18 664 463 950). Operating entity: Evalify Pty Ltd (ABN 32 664 474 980). References to “Nullify”, “we”, “us”, and “our” cover the Nullify service and website operated by these entities in their stated roles.

Nullify acts as a controller for website visitors, prospects, applicants, and platform-account administration. When we process customer repositories, infrastructure, findings, and related user mappings to provide the contracted security service, we generally act as a processor on the customer’s instructions.

Privacy requests: Email support@nullify.ai. EEA residents may also contact our EU representative, Prighter.

What we process and why

We collect only the personal information reasonably needed for the purposes below. The applicable legal basis depends on the relationship and jurisdiction.

ContextDataPurposeGDPR basisSource
Website and consentIP address, device/browser data, consent choice, page and campaign interactionsOperate the site, remember privacy choices, measure performance, and—only with marketing consent—understand business interest and attributionLegitimate interests for essential security/operation; consent for optional analytics and marketingYour browser and consent choices
Enquiries and demosName, business email, company, role, message, meeting detailsRespond to requests, arrange demonstrations, and manage the prospective customer relationshipSteps at your request before contract; legitimate interests; consent where requiredYou, your employer, or publicly available professional sources
Platform accountsName, work email, account identifiers, authentication and audit recordsProvide, secure, support, and administer the serviceContract; legitimate interests in service security; legal obligationsYou, your organization, and connected identity providers
Customer security operationsProfessional identifiers, repository authorship, ownership mappings, finding and workflow activityDeliver vulnerability detection, validation, remediation, routing, reporting, and support on customer instructionsCustomer-determined basis; contract for account administrationCustomer-authorized systems and integrations
RecruitmentName, contact details, résumé/CV, work history, interview notes, eligibility and voluntarily supplied informationAssess applications, communicate with candidates, protect the hiring process, and meet employment-law obligationsSteps before contract; legitimate interests in recruitment; legal obligations; consent for optional future opportunities where requiredYou, referees you nominate, recruiters, and professional sources

We do not sell personal information. We do not use personal information for solely automated decisions that produce legal or similarly significant effects about an individual.

Cookies and optional website technologies

Essential code may run to serve the website, prevent abuse, and remember your privacy choice. Optional analytics and marketing technologies should remain disabled until you make an affirmative choice. You can reopen Cookie settings from every page to change or withdraw that choice.

CategoryProviderPurposeWhen usedStorage/retention
EssentialNullify / WebflowDeliver the site, maintain security, and remember consent preferencesAlwaysSession or consent-version duration, as necessary for the stated purpose
AnalyticsGoogle AnalyticsAggregate page and conversion measurement used to improve site performanceOnly after Analytics consentIdentifiers and event retention follow our configured analytics settings and your withdrawal choice
CRM and attributionHubSpotProvide requested forms/meetings and, with Marketing consent, associate campaign interactions with business enquiriesCore forms must remain usable after rejection; optional tracking only after Marketing consentContact records are retained for the relationship and applicable legal needs; optional identifiers stop when consent is withdrawn
Visitor identificationReo.devWith Marketing consent, understand organizational interest in NullifyOnly after Marketing consent; excluded from applicant résumé data and form valuesSubject to configured vendor retention and deletion controls
Campaign attributionLinkedInWith Marketing consent, measure campaign performanceOnly after Marketing consent; no résumé, application-field, or free-text contentSubject to configured campaign retention and withdrawal controls

Browser settings can also restrict storage, but using our Cookie settings control is the clearest way to express a site-specific choice. Withdrawing consent does not affect processing that occurred lawfully before withdrawal.

Applicant privacy

When you apply for a role, we use your application information only to assess and administer recruitment, communicate with you, prevent fraud, and meet legal obligations. We do not send résumé content, filenames, form values, or interview notes to advertising or visitor-identification tools.

Application information is retained for the hiring process and any legally required period. We retain information for unrelated future roles only when there is a valid basis and appropriate notice or consent. You may request access, correction, or deletion using the contact details below, subject to legal exceptions.

Recipients and international transfers

We may share personal information with personnel and service providers that need it to operate the service, including hosting, identity, communications, customer-support, recruitment, professional-advisory, and—where you consent—website analytics and marketing providers. We may also disclose information when required by law, to protect rights and security, or as part of a legitimate corporate transaction.

Nullify is based in Australia and uses providers in Australia, the United States, the European Economic Area, and other locations. Where GDPR-restricted data is transferred outside the EEA, UK, or Switzerland, we use an available lawful mechanism such as an adequacy decision or Standard Contractual Clauses and supplementary technical or organizational safeguards. You may request information about applicable safeguards.

Retention and security

  • Identity and contact data: for the account or business relationship and up to two years afterward where needed for reactivation, records, disputes, or legal obligations.
  • Technical and usage data: for the period required for security, incident investigation, consent records, and configured measurement—generally no longer than two years unless a shorter vendor or consent period applies.
  • Profile data: for the account and ordinarily deleted within 90 days after account closure, subject to legal exceptions.
  • Customer source code: accessed for authorized security work and handled according to the customer agreement and data-processing terms; scan results follow the contracted retention schedule.
  • Applications: for the recruitment process and any legally necessary period, with longer talent-pool use only under an appropriate basis.

We use administrative, technical, and physical safeguards designed to protect information, including access control, encryption in transit and at rest where applicable, logging, minimization, and deletion or anonymization processes. No internet service can guarantee absolute security.

Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port personal information; object to certain processing; withdraw consent; and complain to a supervisory authority. EEA, UK, and Swiss requests are ordinarily free. A reasonable fee or refusal may apply only where permitted for manifestly unfounded or excessive requests.

We acknowledge requests promptly and ordinarily respond within one month under GDPR, subject to permitted extensions and identity verification. California and other US residents may also have rights to know, correct, delete, opt out, and receive equal service. Nullify does not sell personal information or share it for cross-context behavioral advertising.

Product agreements and supporting documents

The contract governing a customer’s use of Nullify may include an order form, enterprise agreement, data-processing agreement, and service-specific terms. Contact us for the documents applicable to your organization.

Contact and complaints

Email support@nullify.ai for privacy questions, data-subject requests, or complaints. EEA residents may contact Prighter or lodge a complaint with their local supervisory authority. Australian residents may contact the Office of the Australian Information Commissioner.

We may update this notice when our services, providers, or legal obligations change. Material changes will receive an updated effective date and, where required, a new consent request or direct notice.