Your data. Your choices. Clear terms.
This page explains how Nullify handles personal information, how optional website technologies work, and how to exercise your privacy rights. Product-specific contractual terms and data-processing documents are also available below.
Effective: 26 July 2026 · Last updated: 26 July 2026
Privacy notice
Controller: Nullify Holdings Pty Ltd (ABN 18 664 463 950). Operating entity: Evalify Pty Ltd (ABN 32 664 474 980). References to “Nullify”, “we”, “us”, and “our” cover the Nullify service and website operated by these entities in their stated roles.
Nullify acts as a controller for website visitors, prospects, applicants, and platform-account administration. When we process customer repositories, infrastructure, findings, and related user mappings to provide the contracted security service, we generally act as a processor on the customer’s instructions.
What we process and why
We collect only the personal information reasonably needed for the purposes below. The applicable legal basis depends on the relationship and jurisdiction.
| Context | Data | Purpose | GDPR basis | Source |
|---|---|---|---|---|
| Website and consent | IP address, device/browser data, consent choice, page and campaign interactions | Operate the site, remember privacy choices, measure performance, and—only with marketing consent—understand business interest and attribution | Legitimate interests for essential security/operation; consent for optional analytics and marketing | Your browser and consent choices |
| Enquiries and demos | Name, business email, company, role, message, meeting details | Respond to requests, arrange demonstrations, and manage the prospective customer relationship | Steps at your request before contract; legitimate interests; consent where required | You, your employer, or publicly available professional sources |
| Platform accounts | Name, work email, account identifiers, authentication and audit records | Provide, secure, support, and administer the service | Contract; legitimate interests in service security; legal obligations | You, your organization, and connected identity providers |
| Customer security operations | Professional identifiers, repository authorship, ownership mappings, finding and workflow activity | Deliver vulnerability detection, validation, remediation, routing, reporting, and support on customer instructions | Customer-determined basis; contract for account administration | Customer-authorized systems and integrations |
| Recruitment | Name, contact details, résumé/CV, work history, interview notes, eligibility and voluntarily supplied information | Assess applications, communicate with candidates, protect the hiring process, and meet employment-law obligations | Steps before contract; legitimate interests in recruitment; legal obligations; consent for optional future opportunities where required | You, referees you nominate, recruiters, and professional sources |
We do not sell personal information. We do not use personal information for solely automated decisions that produce legal or similarly significant effects about an individual.
Applicant privacy
When you apply for a role, we use your application information only to assess and administer recruitment, communicate with you, prevent fraud, and meet legal obligations. We do not send résumé content, filenames, form values, or interview notes to advertising or visitor-identification tools.
Application information is retained for the hiring process and any legally required period. We retain information for unrelated future roles only when there is a valid basis and appropriate notice or consent. You may request access, correction, or deletion using the contact details below, subject to legal exceptions.
Retention and security
- Identity and contact data: for the account or business relationship and up to two years afterward where needed for reactivation, records, disputes, or legal obligations.
- Technical and usage data: for the period required for security, incident investigation, consent records, and configured measurement—generally no longer than two years unless a shorter vendor or consent period applies.
- Profile data: for the account and ordinarily deleted within 90 days after account closure, subject to legal exceptions.
- Customer source code: accessed for authorized security work and handled according to the customer agreement and data-processing terms; scan results follow the contracted retention schedule.
- Applications: for the recruitment process and any legally necessary period, with longer talent-pool use only under an appropriate basis.
We use administrative, technical, and physical safeguards designed to protect information, including access control, encryption in transit and at rest where applicable, logging, minimization, and deletion or anonymization processes. No internet service can guarantee absolute security.
Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal information; object to certain processing; withdraw consent; and complain to a supervisory authority. EEA, UK, and Swiss requests are ordinarily free. A reasonable fee or refusal may apply only where permitted for manifestly unfounded or excessive requests.
We acknowledge requests promptly and ordinarily respond within one month under GDPR, subject to permitted extensions and identity verification. California and other US residents may also have rights to know, correct, delete, opt out, and receive equal service. Nullify does not sell personal information or share it for cross-context behavioral advertising.
Product agreements and supporting documents
The contract governing a customer’s use of Nullify may include an order form, enterprise agreement, data-processing agreement, and service-specific terms. Contact us for the documents applicable to your organization.
Contact and complaints
Email support@nullify.ai for privacy questions, data-subject requests, or complaints. EEA residents may contact Prighter or lodge a complaint with their local supervisory authority. Australian residents may contact the Office of the Australian Information Commissioner.
We may update this notice when our services, providers, or legal obligations change. Material changes will receive an updated effective date and, where required, a new consent request or direct notice.