Skip to main content

Privacy Policy

Effective 31 July 2026

This policy explains how Yuma IT Pty Ltd (ABN 62 684 389 839) handles personal information collected through Banksia. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

1. Who we are

Banksia is a website health and AI visibility assessment service operated by Yuma IT Pty Ltd (ABN 62 684 389 839) (“we”, “us”, “our”). Yuma IT Pty Ltd is the parent company of the Banksia service and the entity responsible for personal information collected through it.

If you have a question about this policy or about how we handle your information, contact us at [email protected].

2. What we collect

We collect only what we need to deliver the service.

Assessment requests

When you request an assessment we collect the website address you submit, your business email address, your business name where you provide it, the time you gave consent, and the IP address and browser user agent of the submitting device.

Booking requests

When you request a session we collect your email address, business name, website address, preferred times, timezone, any message you write, and the IP address and browser user agent of the submitting device.

Account information

If an account is created for you, we hold your name, email address, an optional profile image, a hashed representation of your password, and the configuration of any multi-factor method you enable — an authenticator app, single-use recovery codes, or passkeys. We never store your password in a readable form.

Assessment output

We store the results of the assessment: scores, findings, extracts of the public pages examined, and the report generated from them. This material describes your website. It may incidentally contain personal information where your website already publishes it — a staff name on a contact page, for instance.

Records of activity

We keep an audit record of security-relevant actions, covering the acting account, the action, the affected record, and the IP address and user agent involved. We also keep operational logs. Passwords, tokens, cookies and authorisation headers are stripped from logs before they are written.

What we do not collect

We do not ask for and do not want credentials or administrative access to your website, and we never examine anything behind a login. We do not collect payment card details through this site. We do not collect sensitive information as defined by the Privacy Act, and we ask that you do not send it to us.

3. Why we collect it

We use personal information to:

  • confirm you control the email address given, before any crawling begins;
  • run the assessment and produce your report;
  • respond to booking requests, and arrange and hold review sessions;
  • quote, scope and deliver remediation work where you ask us to;
  • protect the service from automated abuse, apply rate limits, and investigate misuse;
  • meet our legal, accounting and record-keeping obligations; and
  • improve the accuracy of our assessment rules — using aggregate information, not by singling out your business.

We do not sell personal information. We do not use your information to build advertising profiles, and we do not disclose it for another organisation’s marketing.

4. Direct marketing

If you have asked us for an assessment or a booking, we may contact you about that request and about closely related services. Every such message includes a way to opt out, and we will stop on request. You can opt out at any time by replying to any message from us, or by emailing [email protected].

5. Who we share it with

We disclose personal information to service providers who help us run Banksia, and only for that purpose. They are bound to protect it and may not use it for their own ends. These are:

  • Website scanning providers — to fetch the public pages of the website being assessed and run our checks against them.
  • Email delivery providers — to send verification, transactional and booking messages.
  • Bot-protection providers — to distinguish genuine form submissions from automated ones.
  • Team messaging providers — to alert our team in a private channel that a form has been submitted, so that someone attends to it. What is sent is limited to the type of form, the website or business name it concerns, and a link into our own staff area.
  • Customer relationship management providers — to keep a record of an enquiry so our team can follow it up. What is sent is limited to your email address, the website address or business name the enquiry concerns, which form you used and when, and a link into our own staff area.
  • Professional advisers — legal, accounting and insurance, where relevant.

We run the application, its database and its file storage on infrastructure we operate ourselves, so no third-party hosting provider holds this information. We do not currently use an external monitoring, error-reporting or analytics provider.

We may also disclose information where required or authorised by Australian law, to enforce our Terms of Service, or to protect the rights or safety of any person. If our business or the Banksia service is sold or restructured, information may transfer to the acquirer, who would remain bound by this policy or one materially equivalent.

A current list of our service providers — naming each one, what it receives and where it processes it — is published at Subprocessors, and is also available on request from [email protected].

6. Overseas disclosure

We prefer to keep data in Australia. The application, its database and its file storage run on infrastructure we operate ourselves rather than on a third-party cloud platform.

Four of the services we rely on operate outside Australia, or may do:

  • Website scanning and bot protectionrun on Cloudflare’s network. Cloudflare answers a request from whichever of its locations is nearest, so this processing may occur in any country in which Cloudflare operates, not only in Australia. Which location handles a given request is determined by that network and is not something we choose. Cloudflare is a United States company.
  • Email delivery is handled by Resend, a United States company, and our messages are processed in the United States.
  • Staff notifications, where we have enabled them, are sent to Slack, a United States company, and are processed in the United States. When one of our public forms is submitted, a message is posted to a private channel so our team attends to it. That message carries the type of form, the website address or business name it concerns, the preferred times and timezone on a booking request, and a link into our own staff area. It also carries the email address you gave us, so we can reply to you, and it never carries an assessment, a report or anything from an account. Where we have not enabled these notifications, nothing is sent to Slack.
  • Customer relationship management, where we have enabled it, is provided by Attio. When one of our public forms is submitted we create or update a record of the enquiry so our team can follow it up. That record carries the email address you gave us, the website address or business name it concerns, which form you used and when, the preferred times and timezone on a booking request, and a link into our own staff area. It never carries an assessment, a report or anything from an account. We send this to Attio’s own service rather than to infrastructure we operate, and we do not choose where it is processed. We have not confirmed a processing country for Attio and will not claim one, so you should assume it may be handled outside Australia; we will confirm the current position in writing on request. Where we have not enabled this, nothing is sent to Attio.

Where information is handled outside Australia we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles. What each provider receives is set out at Subprocessors.

If the hosting location of your data matters for a procurement or vendor assessment, contact us and we will confirm the current position in writing.

7. How we protect it

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Those steps include encryption in transit, encrypted storage, server-side authorisation on every request, separation of each customer’s data, multi-factor authentication for staff access, least-privilege access reviewed when roles change, and audit logging of security-relevant actions.

Our Security page sets out these controls in more detail and explains how to report a vulnerability.

No online service can promise perfect security. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

8. How long we keep it

We keep personal information only while we need it, then delete or de-identify it.

  • Unverified assessment requests — deleted 30 days after submission if the email address is never confirmed.
  • Assessments and reports — retained for 24 months from generation, so results can be compared over time, then deleted or de-identified.
  • Booking requests and enquiry correspondence — retained for 24 months from last contact.
  • Accounts — retained while the account is active, then deleted within 90 days of closure.
  • Security and audit records — retained for 12 months.
  • Records we must keep by law — financial records relating to paid work, retained for seven years as required by Australian tax law.

Where we are required to keep a record for a legal reason we will retain it for that reason alone, even if you have asked us to delete it, and we will tell you when that applies.

9. Accessing and correcting your information

You may ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. You may also ask us to delete information we are not required to keep. Email [email protected] and we will respond within 30 days.

There is no charge to make a request. We may ask you to verify your identity before we act on one. If we refuse a request we will tell you why in writing, and explain how to complain about that decision.

10. Cookies and analytics

We use cookies that are necessary for the service to function — for example to keep you signed in, and to protect forms against automated abuse. These cannot be turned off without breaking the service.

We do not use advertising cookies, and we do not permit third parties to track you across other websites through Banksia. You can block or delete cookies in your browser settings, though signed-in features will stop working if you block the necessary ones.

11. Children

Banksia is a service for businesses and organisations and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.

12. Complaints

If you think we have breached the Australian Privacy Principles, email [email protected] with the details. We will acknowledge your complaint within five business days and give you a written response within 30 days.

If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au/privacy/privacy-complaints (opens in a new tab), or by phone on 1300 363 992.

13. Changes to this policy

We may update this policy as the service changes. The effective date at the top of this page shows when it last changed. If a change materially affects how we handle your personal information, we will take reasonable steps to tell you before it takes effect.