Our data handling policy
unphish Pty Ltd
1. Introduction
unphish (“we”, “our”, “us”) is committed to protecting the privacy and security of our clients’ data.
This statement outlines how we collect, use, store, and protect information in connection with our brand protection and threat intelligence services.
2. Information We Collect
We collect and process data necessary to deliver our services, including:
- Threat intelligence data (e.g. domains, URLs, and related indicators)
- Enforcement case information (including supporting evidence such as screenshots)
- Client account and configuration information
- System usage and audit logs
- Communications and support interactions
We do not collect personal information unless it is necessary for service delivery or provided by the client.
3. How We Use Information
We use collected data to:
- Identify, assess, and respond to online threats
- Conduct enforcement actions on behalf of clients
- Maintain platform functionality and security
- Provide reporting, analytics, and insights
- Meet legal, regulatory, and contractual obligations
4. Data Retention
We retain data only for as long as necessary to provide our services and meet legal or operational requirements.
In general:
- Active client data is retained for the duration of the client relationship
- Certain enforcement-related records may be retained beyond termination for legal, audit, or evidentiary purposes
- Non-essential or temporary data is deleted or anonymised within defined timeframes
5. Data Security
We implement appropriate technical and organisational measures to protect data, including:
- Access controls and role-based permissions
- Data segregation between clients
- Secure storage and transmission practices
- Monitoring and audit logging
6. Data Sharing
We do not sell client data.
We may share data with:
- Trusted service providers and partners required to deliver our services
- Registrars, hosting providers, or platforms as part of enforcement actions
- Authorities where required by law
All third parties are subject to appropriate confidentiality and security obligations.
7. International Data Transfers
Where data is transferred across jurisdictions, we take steps to ensure it remains protected in accordance with applicable data protection laws.
8. Data Rights & Requests
Depending on applicable laws and contractual agreements, clients may request:
- Access to their data
- Correction of inaccurate data
- Deletion of data (where legally permissible)
Requests can be submitted using the contact details below.
9. Data Retention Exceptions
We may retain data for longer periods where required for:
- Legal obligations
- Dispute resolution or enforcement
- Regulatory or audit requirements
10. Changes to This Statement
We may update this statement from time to time. Updates will be published on our website.
11. Contact Us
For any questions or data requests, please contact:
Email: [email protected]
Company: unphish Pty Ltd