Privacy Policy

Last updated: 28 August 2026

1. Introduction

Wytness ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share information when you use our platform, websites, SDKs, APIs, and related services (collectively, the "Service"). It applies to account holders, members of customer organisations, and visitors to our marketing website.

Wytness is a registered business name of Providence Tech Pty Ltd, ABN 16 685 892 513, a company incorporated in Australia. References to "Wytness" in this Privacy Policy are to Providence Tech Pty Ltd carrying on business as Wytness.

2. Information We Collect

Account Information

When you create an account we collect your name, email address, organisation name, role, time-zone preference, and password (stored as a bcrypt hash; we never store plaintext passwords). Email verification uses a six-digit code with a 15-minute expiry.

Audit Event Data

Your AI agents submit audit events through our SDKs. Each event contains metadata (agent identifier, tool name, timestamp, session identifier, hash chain step) and any payload your integration includes. Event payloads are cryptographically signed by Ed25519 keys generated and held in your environment; only the corresponding public keys are registered with Wytness. We process and store this data solely to provide the Service.

Operational Records

To run the platform reliably we keep records of API key usage, webhook deliveries, in-app notifications and read state, data integrity check results, chain-break investigations, and administrative actions in a platform audit log.

Usage Data

We collect basic usage data such as login timestamps, pages visited within the dashboard, API call volumes, and error/diagnostic telemetry. We use this data to operate, secure, and improve the Service.

Billing Information

Billing details (cardholder name, billing address, last four digits of payment method, invoice history) are processed through our payment partners. Wytness does not store full card numbers. If your subscription is fulfilled through a cloud marketplace, billing identifiers from that marketplace are stored in place of direct card details.

3. Lawful Basis for Processing

Where the GDPR or UK GDPR applies, we rely on the following lawful bases:

  • Contract: to provide the Service you have signed up for
  • Legitimate interests: to secure the platform, prevent abuse, and improve features
  • Legal obligation: to comply with tax, accounting, and lawful requests from authorities
  • Consent: for any optional communication or feature you actively opt into

4. How We Use Your Information

  • To provide, maintain, secure, and improve the Service
  • To process billing and manage your subscription
  • To send transactional emails (verification codes, invoices, anomaly alerts, integrity warnings, team activity)
  • To detect and prevent fraud, abuse, or security incidents
  • To respond to support enquiries and security questionnaires
  • To comply with legal and regulatory obligations

We do not sell your personal information. We do not use Your Data for advertising or for training machine-learning models.

5. Where Your Data Is Stored

Wytness operates on enterprise-grade cloud infrastructure with managed identity authentication, network isolation, role-based access control, and automated backups. Audit events are written to append-only storage governed by a storage-tier retention lifecycle policy. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Specific infrastructure providers are listed on our Sub-processors page.

Primary processing region: Wytness-hosted customer data is processed and stored in Australia East (Sydney). Database backups are geo-replicated to a secondary Australian region (Australia Southeast, Melbourne) for disaster recovery; the audit archive uses geo-redundant storage within Australia (primary Australia East, paired Australia Southeast). All data remains within Australia unless an alternative region is contractually agreed. The dashboard and marketing web front-ends are served as static assets from the cloud provider's closest available region (currently East Asia, as the static-hosting service does not yet offer an Australia region); these surfaces serve JavaScript and CSS bundles only and do not store audit event data or organisation records.

Business plan with customer-hosted storage: if your organisation is on the Business plan with customer-hosted storage configured, audit event content is written directly to storage in your own cloud tenancy. Wytness routes and verifies the events but does not retain a copy in our shared infrastructure. The metadata required to operate the Service (organisation, agent, signing key references, integrity check results) remains in our control plane.

6. Data Retention

  • Account data: retained while your account is active, plus 30 days after termination in the active store, with Postgres point-in-time recovery images ageing out over the subsequent 35 days
  • Audit events (shared storage): retained per your plan's retention period (compliance archive up to 7 years) while your subscription is active; on cancellation, sealed Evidence Packs covering your full history are generated for you, and audit data is permanently deleted after a 30-day hold
  • Audit events (customer-hosted storage): retained for as long as you keep them in your tenancy; Wytness does not delete from your storage
  • In-app notifications: retained for 90 days
  • Platform audit log: retained indefinitely as a tamper-evident record of administrative actions. Denormalised email and identifier fields persist even after account deletion under the legitimate-interest carve-out (GDPR Article 17(3)(b)) — same basis as audit events. On account deletion the user-id foreign key is set to NULL so audit rows can no longer be correlated to the deleted account by foreign-key join, but the rows themselves are preserved for SOC 2 / EU AI Act / ISO 27001 evidence-retention requirements
  • Usage and operational telemetry: retained indefinitely (aggregate counts, no personal identifiers)
  • Billing records: retained for the period required by applicable tax law (typically 7 years)
  • Marketing capture (waitlist signups, contact-form submissions): retained for 365 days (waitlist) or 730 days (contact form) and then hard-deleted by the retention reaper

7. Sharing With Third Parties

We share data with third-party sub-processors only to deliver the Service (cloud infrastructure, payment processing, transactional email, edge protection, observability). Each sub-processor receives only the minimum data required for its function. We also disclose information where required by law, court order, or to protect the security of the Service. A current list of sub-processors is published at /sub-processors.

8. Cookies and Local Storage

Wytness sets no cookies. The dashboard uses essential first-party browser storage (localStorage) for authentication (JWT access and refresh tokens) and session preferences. The marketing website sets no tracking, advertising, or third-party analytics cookies either; the only values it stores in your browser are your banner choice and theme preference, both first-party and essential. Impersonation tokens used by support staff are kept in session-only storage and cleared when the browser tab closes.

9. Communications

Transactional emails (verification, billing, security alerts, service notices) are essential to the Service and cannot be opted out of while you hold an account. We do not send marketing email by default. If we introduce optional product updates or newsletters in future, they will be opt-in and include an unsubscribe link in every message.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data, subject to legal retention requirements
  • Export your data in a machine-readable format
  • Object to or restrict certain processing activities
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with your local data protection authority

California residents (CCPA/CPRA): you may request the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of recipients. We do not sell or share personal information for cross-context behavioural advertising and do not offer financial incentives in exchange for personal information.

Automated decision-making (GDPR Article 22): Wytness does not make automated decisions that produce legal or similarly significant effects about you. The platform records decisions made by AI agents that our customers operate; it does not make them. For our customers, the audit trail is evidence supporting the safeguards Article 22(3) requires of them — human intervention, contestability, and review of what an agent actually did.

To exercise any of these rights, contact us at support@wytness.ai. We will respond within the period required by applicable law.

11. International Transfers

Your data may be processed in regions where our infrastructure and sub-processors operate. Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (with the UK Addendum or the Swiss equivalent where applicable) and apply additional safeguards such as encryption in transit and at rest.

12. Security

We protect your data with edge-layer firewall and DDoS protection, TLS 1.2+ encryption in transit, AES-256 encryption at rest, Ed25519 cryptographic signatures on every event, SHA-256 hash chains for tamper detection, role-based access control, managed-identity service-to-service authentication, automated backups with documented recovery procedures, and a platform audit log of administrative actions. See our Trust Centre for the full security overview.

13. Your Privacy Rights: How To Use Them

Under the GDPR (if you are in the European Economic Area or the UK), the Australian Privacy Act 1988, and equivalent regimes, you have rights to access, correct, delete, and port your personal data.

  • Access (DSAR). Sign in to app.wytness.ai → Account → Profile → "Download DSAR" for an immediate JSON export of everything we hold about you (audit events you authored as an operator are capped at 10,000 rows in the immediate export, and the export says so when the cap is reached; a background export is available for a complete, uncapped history and reports any section it could not read rather than omitting it silently). The export is org-scoped; if you belong to multiple organisations, request once per org. Schema reference:docs/dsar-schema.md.
  • Correction. Edit your name, email, timezone, and theme via Account → Profile. Audit-event content cannot be amended after capture (the platform's tamper-evident log is its core property); for an annotation or correction note alongside an event, contact support.
  • Erasure. Account → Profile → Delete Account schedules your account for hard deletion in 30 days. The window lets you cancel via support. After 30 days, the retention reaper hard-deletes your account row and notifies sub-processors via the mechanism appropriate to each: programmatic erasure via the sub-processor's API where one is exposed (payment processor), suppression-list reliance where the sub-processor manages contact-status via webhook (transactional email), and log-retention rollover against the sub-processor's published policy for the edge, CI/CD, and marketplace billing partners. See /sub-processors for the per-vendor flow-down mechanism. Audit events you produced as an operator remain in the organisation's append-only archive for as long as the organisation subscribes (compliance archive up to 7 years) under the legitimate-interest exception of GDPR Article 17(3)(b); operator email addresses on those audit-trail rows are retained on the same basis; these are your organisation's evidence record and are not yours to delete. For full-organisation erasure, the organisation owner must contact support; see Data Processing Agreement Section 11 for the legitimate-interest disclosure.
  • Portability. The DSAR export is JSON, machine-readable, ready to ingest into another system. Bulk audit-event export (CSV / JSONL / registry formats) is also available via Export.
  • Response time. We aim to fulfil DSAR / correction / erasure requests within 30 days, with a possible 60-day extension for complex requests, per GDPR Article 12 and Australian Privacy Principle 12.

If your data is inside an audit event captured by an organisation that uses Wytness (for example, you spoke to an AI agent operated by one of our customers), that organisation is the data controller. Contact them first; we'll support them in fulfilling your request as the data processor.

For Wytness customers fulfilling their end-users' requests: we expose an org-scoped search endpoint (POST /auth/org/subject-search, gated to your org's owners and admins) that scans your audit events for an end-user's identifier or email substring and returns a count + capped sample with redaction guidance. This lets your privacy officer locate every relevant audit event in your tenancy when fulfilling a GDPR Article 15 or 17 request you've received as the controller. The dashboard exposes this workflow as the Subject lookup page (Compliance → Subject lookup): an owner or admin computes the subject's pseudonym token in the browser and retrieves every matching event, without the HMAC secret or the raw identifier leaving the tab. Wytness does not access the contents of your audit events except to operate the service.

When an erasure run reports partial completion. A redaction run scrubs the live event store and every archive copy of the events it matched. If an archive copy cannot be rewritten — for example while your own storage account is unreachable under bring-your-own-storage — the run finishes as completed with failures and reports how many copies it could not reach. It never reports plain success it did not earn. Those copies still hold the subject's data, so the request is not yet fulfilled: restore access to the archive and start the redaction again. Repeating a redaction is safe — it re-matches whatever remains and leaves already-scrubbed events untouched.

Backups and recovery copies. Deleted or erased data may persist in encrypted database point-in-time recovery images for up to 35 days and in storage soft-delete recovery copies for up to 14 days after deletion. These copies age out automatically, are not queried in normal operation, and are restored only in a documented disaster-recovery or erasure-undo procedure.

Erasure and verifiability. An erasure permanently removes the retained signed payload of each matched event. The event's metadata and signature record remain in the archive, but that event can no longer be independently re-verified offline, and Evidence Packs disclose this per event rather than presenting it as verifiable. If an erasure request overlaps a period an auditor may later examine, weigh this consequence before submitting the request — it cannot be reversed after the recovery window closes.

14. Cross-Border Transfers

Operational data (databases, blob storage, compute) is hosted in Australia East (Sydney) by default and remains in the region in which your organisation is provisioned. We do not move operational data to other regions except where an alternative region is contractually agreed and provisioned for your organisation.

A small number of sub-processors operate globally and may process limited data outside Australia (payment processing data, transactional email content, and request metadata traversing a global edge network). Standard contractual clauses and equivalent transfer mechanisms are in place. The current list with what each processes lives at /sub-processors.

15. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify account holders of material changes via email or through the dashboard. The "Last updated" date at the top indicates when this policy was last revised.

17. Contact

For privacy enquiries, data subject requests, or to ask about cross-border transfers, contact us at support@wytness.ai.

We set no cookies. Sign-in and preferences use essential first-party browser storage only — no tracking, advertising, or third-party analytics. Privacy Policy

1. Introduction
TABLE OF CONTENTS