Privacy Policy

Last updated March 2026. This policy explains how Cert Ready handles your data.

What we collect

When you use Cert Ready, we collect:

  • Account information — your email address (used for magic link authentication)
  • Organisation details — company name, industry, and employee count (provided during onboarding)
  • Assessment responses — your answers to ISO readiness questions, including optional evidence notes
  • Assessment results — scores, identified gaps, and generated recommendations

How we use your data

Your data is used to:

  • Deliver the assessment service (scoring, gap identification, recommendations)
  • Generate your gap report and readiness certificate
  • Save your progress so you can resume assessments
  • Send transactional emails (magic link sign-in, assessment completion)

All scoring and gap identification is performed by deterministic rules-based logic. No AI APIs or machine learning models process your assessment data.

Data storage

Your data is stored in Supabase, which uses Amazon Web Services (AWS) infrastructure. Our database is hosted in the ap-southeast-2 (Sydney) region.

Data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256.

Third-party services

We use the following third-party services:

  • Supabase — database, authentication, and row-level security (data hosted in AWS Sydney)
  • Cloudflare Pages — frontend hosting and CDN

We do not sell, rent, or share your data with third parties for marketing purposes.

Your rights

Under the Australian Privacy Principles (APPs), you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your account and associated data
  • Export your assessment data

To exercise any of these rights, contact us at privacy@isoselfcheck.com.au.

Contact

For privacy-related enquiries, email privacy@isoselfcheck.com.au.

Start free assessment →