Privacy Policy
Effective: 7 August 2026 · Version 2.0
This is a living document, reviewed and updated regularly as our practices evolve. The online version is always the most current.
GetPost Labs Pty Ltd (ABN 82 634 520 924) builds and operates its own software products and provides software development and technology consulting services to clients. We are committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This is the company-wide privacy policy for GetPost Labs. It explains what personal information we collect across our business, why we collect it, how we hold and share it, how long we keep it, and how you can access it, correct it or make a complaint.
Lex-AML has its own privacy policy. If you use the Lex-AML platform, the Lex-AML mobile applications or the Lex-AML Training Academy, the policy that governs your personal information is lex-aml.com.au/privacy — not this page. That policy is the single source of truth for the Lex-AML product, including its apps and their users. This page does not repeat it.
1Who We Are
GetPost Labs Pty Ltd is an Australian company based in Brisbane, Queensland. We do two kinds of work: we build and operate our own software products, and we provide software development, architecture and cloud consulting services to client organisations. Our current product is Lex-AML, an AML/CTF compliance platform.
We are the entity responsible for the personal information described in this policy. For any privacy question, request or complaint, contact us using the details below.
- Entity
- GetPost Labs Pty Ltd · ABN 82 634 520 924
- Contact
- Sumit Arora, Founder & Director
- sumit@getpostlabs.io
- Address
- 8 Clunies Ross Ct, Brisbane Technology Park, Queensland 4113
- Website
- https://getpostlabs.io
2What This Policy Covers
This policy covers personal information GetPost Labs handles as a company:
- This website — visitors to getpostlabs.io.
- Business contacts and clients — people we deal with when quoting for, contracting and delivering work, and when selling and supporting our products.
- Consulting engagements — personal information we encounter in a client's systems or data while performing services for that client.
- Job applicants and contractors — people who apply to work with us or who supply services to us.
What this policy does not cover. It does not cover the personal information handled inside our products. Each product has its own privacy policy, which governs the people who use that product:
- Lex-AML — including the Lex-AML platform, its mobile applications and the Lex-AML Training Academy — is governed by lex-aml.com.au/privacy.
- Other products — where a product has its own policy or a customer-specific agreement, that document governs use of that product. We will tell you which policy applies before you start using it.
It also does not cover third-party websites we link to. Those sites have their own privacy policies and we are not responsible for them.
3What Personal Information We Collect
What we collect depends on your relationship with us. In most cases it is limited business-contact information.
Website visitors. When you visit getpostlabs.io we collect technical information through analytics — IP address, approximate location, device and browser type, pages viewed, referring site and time of visit. This website has no sign-up, no account and no submission forms; if you want to contact us, you email us directly.
Enquiries and business contacts. If you email us or connect with us, we hold your name, your email address and any other contact details, your role and organisation, and the content of your correspondence with us.
Clients and prospective clients. To quote for, contract and deliver work — and to sell and support our products — we hold the name and contact details of your authorised representatives and day-to-day contacts, your organisation name, ABN/ACN and registered address, and billing, subscription and payment records.
Consulting engagements. While performing services, we may be given access to systems or data belonging to a client that contain personal information about that client's own staff, customers or suppliers. We access that information only to perform the engagement, on the client's instructions and under the engagement agreement. The client remains responsible for that information and its own privacy obligations; we do not use it for our own purposes.
Job applicants. If you apply for a role, we hold what you send us — your name and contact details, résumé or CV, work and education history, portfolio or code samples, and any referee details and interview notes.
Suppliers and contractors. We hold contact, contracting and payment details for the people and businesses we engage.
We do not collect government identifiers or health information through this website or in the ordinary course of our consulting business. We do not collect sensitive information unless it is reasonably necessary for our functions and you consent, or the law otherwise permits it. We do not add you to marketing lists without your consent.
Dealing with us anonymously. You can browse getpostlabs.io without identifying yourself. Where it is lawful and practical, you may deal with us anonymously or under a pseudonym — though for contracted work and billing we generally need to know who you are.
Where identity verification, screening or similar checks are performed, that happens inside the relevant product and is described in that product's privacy policy — for Lex-AML, at lex-aml.com.au/privacy.
4How We Collect It
We collect personal information:
- Directly from you — when you email us, meet with us, negotiate or sign an agreement, apply for a role, or supply services to us
- Automatically — through website analytics when you visit getpostlabs.io (see Section 9)
- From your organisation — where a client or supplier gives us contact details for the people we will be working with
- From publicly available and professional sources — such as a company website, a public business register or a professional networking profile
- From a client — where we are given access to that client’s systems or data to perform an engagement
Where we collect personal information about you from someone other than you, and it is reasonable to do so, we will take reasonable steps to make sure you are aware of this policy.
5Why We Collect It
We collect and use personal information only for these purposes:
- To respond to your enquiry and communicate with you
- To quote for, enter into, manage and deliver our services and our products
- To issue invoices, process payments and manage subscriptions
- To provide support, maintain security, and operate, monitor and improve our services and website
- To assess job applications and manage recruitment
- To manage our relationships with suppliers and contractors
- To meet our own legal, tax, accounting, insurance and regulatory obligations
- To establish, exercise or defend legal claims
If we ever want to use your personal information for a different purpose, we will seek your consent unless the law permits or requires the use without it.
6Who We Share It With
We do not sell, rent or trade personal information. We share it only where necessary, and only with:
- Service providers who help us run the business — cloud hosting and infrastructure, email and collaboration tools, website analytics, billing and payment processing, and support tooling — under agreements that limit what they may do with it
- Professional advisors — lawyers, accountants and insurers — where necessary
- A client, where the information relates to an engagement we are performing for that client
- Government agencies, regulators, courts or law enforcement, where required or authorised by Australian law
- A purchaser or successor, if we sell or restructure part of our business, subject to appropriate confidentiality protections
Personal information held inside a product is shared as described in that product's privacy policy, not under this one.
7Overseas Disclosure
We prefer to store personal information in Australia and our primary hosting is in Australian data centre regions. Some of the service providers we rely on — for example website analytics, email and collaboration tools, and payment processing — are operated by companies located overseas, including in the United States and the European Union, or may store or process data overseas.
Before we disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, as required by APP 8. Where a client engagement or a product has specific data-location requirements, those are set out in the relevant agreement or product privacy policy.
8How We Hold and Protect It
We hold personal information in cloud services and business systems operated on our behalf. We protect it with measures appropriate to its sensitivity, including:
- Encryption in transit (TLS 1.2 or higher) and encryption at rest for production data stores
- Access controls, authentication and multi-factor authentication on business and production systems
- Access limited to the people who need it to do their job, on a least-privilege basis
- Logging and monitoring of access to production systems
- Confidentiality obligations on our people, contractors and service providers
- Regular review of our security configuration and of the providers we use
No system can be guaranteed completely secure. We keep our controls under review and respond to incidents as described in Section 11.
9Website, Cookies and Analytics
getpostlabs.io uses Google Analytics to understand how the site is used — which pages are visited, how visitors arrive and how the site performs. This involves cookies and the collection of the technical information described in Section 3. We use it to improve the site, not to build marketing profiles of individuals.
Google Analytics is provided by Google and is subject to Google's own privacy terms. You can manage or block cookies through your browser settings, and you can install Google's browser opt-out add-on. Blocking cookies will not stop you from reading this website.
This website does not host accounts, logins or submission forms.
10How Long We Keep It
We keep personal information only as long as we need it:
- Client, contract, billing and tax records — for the life of the relationship and then for at least seven years, to meet Australian tax, corporate and limitation-period requirements
- Enquiries and general correspondence — generally up to two years from our last contact, unless it forms part of a client record
- Unsuccessful job applications — generally up to twelve months, so we can consider you for future roles, unless you ask us to delete it sooner
- Website analytics — for the retention period configured in our analytics tool, currently up to 14 months
When we no longer need personal information and are not required to keep it, we destroy it or de-identify it. Retention of information held inside a product is governed by that product's privacy policy and the relevant customer agreement.
11Data Breach Response
If a data breach involves personal information we hold, we will assess it promptly under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth). Where a breach is likely to result in serious harm, we will:
- Take immediate steps to contain the breach and limit further harm
- Notify affected individuals as soon as practicable
- Notify the Office of the Australian Information Commissioner (OAIC) as required
- Review what happened and address the cause
Where an incident involves information we handle for a client, or information inside a product, we will work with the relevant client in line with the applicable agreement so that each party can meet its own obligations.
12Access, Correction and Privacy Requests
You may ask us to give you access to the personal information we hold about you, or to correct it if it is inaccurate, out of date, incomplete or misleading. You may also ask us to delete information we no longer need, and ask how we have handled it.
Send your request to sumit@getpostlabs.io. We may need to verify your identity first. We will respond within 30 days and there is no charge for making a request. If we refuse access or a correction, we will tell you why in writing and how to complain.
If your request concerns information held inside a product, make it under that product's privacy policy — for Lex-AML, at lex-aml.com.au/privacy. If your request concerns information we hold on a client's behalf under a consulting engagement, we will refer you to that client, who is responsible for responding.
13Complaints
If you have a concern about how GetPost Labs has handled your personal information, please contact us in the first instance:
Email sumit@getpostlabs.io
Post GetPost Labs Pty Ltd, 8 Clunies Ross Ct, Brisbane Technology Park, Queensland 4113
We will acknowledge your complaint within 5 business days and provide a full response within 30 days. If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):
14Changes to This Policy
This is a living document. As our business and information-handling practices develop, we review and update this policy to reflect them. Updates are published at getpostlabs.io/privacy with a new effective date and version. Where changes are material, we will notify existing customers directly.
This policy is governed by the laws of Queensland, Australia.
GetPost Labs Pty Ltd · ABN 82 634 520 924 | Last updated: 7 August 2026 | Version 2.0