Skip to content
Chinron
Legal

Privacy Policy

Last updated: 20 July 2026

Chinron ("we", "us", "our") is a registered business name of Taruch Pty Ltd (ABN 86 699 259 053), an Australian company. This Privacy Policy explains how we collect, use, store, and disclose personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using the Chinron platform or website, you agree to the practices described in this policy. If you do not agree, please contact us before continuing to use our services.

1. Who this policy applies to

This policy applies to:

  • Administrators — people who manage a Chinron account on behalf of an organisation
  • End users — employees of our customers who access training content
  • Visitors — people who visit our marketing website (chinron.io)
  • Prospects — people who submit enquiry forms or sign up for a trial

2. What personal information we collect

From administrators and prospects

  • Name, work email address, job title, and company name
  • Billing contact information (processed via Stripe — we do not store raw card numbers)
  • Login credentials (passwords are stored only as a secure one-way hash; we never store plaintext passwords)
  • IP address, browser type, and device identifiers collected via server logs

From end users (employees of our customers)

  • Name and work email address (imported by the administrator, or synced from Microsoft 365, Google Workspace or Zoho)
  • Training completion records, quiz scores, and course progress percentages
  • Phishing simulation click/open/report results (used only for risk-score reporting)
  • Deepfake detection and "Spot the Phish" challenge results
  • Points, badges, streaks and leaderboard position, where your organisation has gamification enabled
  • Department, job role, and optional manager information (imported from HR/directory systems)
  • IP address and user-agent collected during login sessions and simulation events

From website visitors

  • Information you voluntarily submit via our contact or trial-signup form (name, email, company, message)
  • Standard server-log data (IP address, pages visited, referrer URL)

We do not use third-party tracking pixels, Google Analytics, Facebook Pixel, or similar advertising trackers on this website.

A note on simulated login pages

Some phishing simulations include a realistic but fake sign-in page. If you type into it, we record only whether the username and password fields were filled — never what you typed. Your keystrokes are not transmitted to us and no password from a simulation is ever stored, logged, or visible to your administrator. This is enforced in the software itself, not merely by policy.

Who can see your data

Your training and simulation results are visible to the administrators of your organisation. If your organisation is managed by an IT provider or Managed Service Provider (MSP) who resells Chinron, that provider's administrators can also see them. Organisations are otherwise fully isolated from one another — no customer can see another customer's data.

Simulation results are intended to measure and reduce organisational risk. How your employer uses them internally is governed by your workplace policies, not by us.

3. How we use your information

  • To provision and operate your Chinron account
  • To deliver cybersecurity awareness training and phishing simulations to your employees
  • To generate training completion and risk-score reports for administrators
  • To send account emails (course reminders, invitation emails, security codes)
  • To send a short series of setup and trial emails to the administrator who signed up. Every one carries an unsubscribe link, and unsubscribing never affects the account emails above.
  • To respond to enquiries submitted via our contact form
  • To manage billing and subscriptions via Stripe
  • To detect and prevent fraud or unauthorised access
  • To improve platform reliability (server logs and error monitoring)

We do not send employee personal information to AI providers. Course and simulation content is generated on demand via the OpenRouter API using your organisation's industry and subject matter only. Employee names, email addresses, performance data and identifiable records are never included in those requests, and therefore cannot form part of any AI provider's training data.

4. Data storage and regional infrastructure

Chinron deploys a separate regional platform for each jurisdiction it operates in, so that employee records stay in the region the organisation operates in. Your data is stored in the region of the platform your organisation is provisioned on.

  • Australia / New Zealand — live. Data stored in Australian data centres.
  • United Kingdom, European Union, United States, Canada — available on request. We stand up a region-native platform before onboarding, so no data is held outside your region in the meantime.

We do not offer self-service signup for a region we have not yet deployed. If you need a region that is not yet live, contact us and we will provision it before your data is collected.

Credentials and sensitive secrets are encrypted at rest. All data in transit is protected by TLS 1.2 or higher.

5. Disclosure to third parties

We use a small number of service providers to operate the platform, covering cloud hosting, email delivery, media storage, payment processing, AI content generation, sales-enquiry management, and — where your administrator enables it — staff directory synchronisation with Microsoft 365, Google Workspace or Zoho. The complete current list, including what each one processes and where it is located, is available on request via our subprocessor register.

Contact details you give us when enquiring or starting a trial are also held in our CRM so we can respond and support your account.

We do not sell, rent, or share personal information with advertisers or data brokers.

We may disclose information if required by law, a court order, or to protect the rights and safety of Chinron, our customers, or the public.

6. Data retention and deletion

  • Active accounts — personal information is retained for the duration of the subscription and 90 days after cancellation, to allow account recovery
  • Account deletion — you can request deletion from your account settings, or by emailing us. Requests are carried out after a 30-day grace period, during which you can cancel. See "How deletion works" below.
  • Abandoned trials — a trial organisation that is never activated is deleted in full, along with its contact record in our CRM, 90 days after the trial lapses
  • Phishing simulation results — click, open and report events are retained for the life of the account so that risk trends can be measured over time. The IP address and browser details attached to an event are removed when the account is deleted.
  • Server logs — retained for up to 12 months for security and troubleshooting purposes
  • Contact form and trial signup submissions — retained in our CRM until the enquiry is resolved or you request deletion

How deletion works

When an account is deleted we irreversibly destroy the information that identifies you — your name, email address, department, job title, session and device records, and the IP addresses and browser details attached to your activity. This cannot be undone or reversed by us.

Your training records are retained without any link to you. Course completions, quiz scores and simulation outcomes remain part of your organisation's historical reporting, but they no longer identify you and cannot be traced back to you. We do this so that deleting one person does not retroactively alter an organisation's compliance history.

Deletion also removes any matching lead record from our CRM. We may retain a minimal record of the deletion itself, and any records we are required to keep by law.

7. Your rights

Under the Australian Privacy Act 1988, you have the right to:

  • Request access to the personal information we hold about you
  • Request correction of inaccurate or outdated information
  • Request deletion of your personal information (subject to legal retention obligations)
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs

Administrators and end users can lodge a deletion request directly from their account settings. Otherwise, email support@chinron.io. We will respond within 30 days.

If you are an employee of one of our customers, we hold your information on your employer's behalf. We will action a request from you directly, and will let your employer know where we are required to.

Data breach notification

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where the breach affects an organisation's employees, we will notify that organisation's administrators without undue delay so they can inform their staff.

8. Cookies and browser storage

The Chinron platform stores the following in your browser:

  • Your login session — an access token held in browser storage, used to keep you signed in. It is cleared when you log out.
  • UI preferences — theme, language, and onboarding progress
  • Your own course notes and bookmarks — these stay in your browser and are not uploaded to our servers

Because your session token and course notes are held locally, we recommend logging out on shared or public computers.

The marketing website (chinron.io) does not use tracking or advertising cookies.

9. Security

We implement industry-standard technical and organisational security measures including:

  • Industry-standard adaptive password hashing — we never store plaintext passwords
  • AES-256 encryption at rest for credentials and sensitive secrets
  • TOTP-based multi-factor authentication (optional for users, enforceable by administrators)
  • Role-based access control with full audit logging
  • TLS 1.2+ for all data in transit
  • Regular dependency audits and security patching

No system is perfectly secure. If you believe you have found a security vulnerability, please email support@chinron.io before disclosing publicly.

10. Children's privacy

The Chinron platform is designed for use in workplace environments. We do not knowingly collect personal information from individuals under the age of 16. If we become aware that a minor has submitted personal information, we will delete it promptly.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to account administrators by email at least 14 days before taking effect. Continued use of the platform after that date constitutes acceptance of the updated policy.

12. Contact us

For privacy-related enquiries, correction requests, or complaints:

  • Email: ask@chinron.io
  • Subject line: "Privacy Enquiry — [your name / company]"

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).