Last updated:
Osmicro Networks Pty Ltd ("Osmicro", "we", "us", or "our") operates the Vukorix platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service. We handle personal information in accordance with the Australian Privacy Principles and hold ourselves to every standard set out in this policy. That is a commitment we make to you and are accountable for. Some obligations bind us as a matter of law whatever our size, and we identify them where they arise: in particular the Privacy (Tax File Number) Rule 2015, and the Notifiable Data Breaches scheme for tax file number information. Where the European Union General Data Protection Regulation applies to something we do, we comply with it.
When you create an account or use the Service, we may collect your name and display name, email address, company name, password (stored as an Argon2id hash; we never store plaintext passwords), mobile number where you enable SMS two-factor authentication or ask us to verify a recipient by SMS (stored encrypted), billing and payment information (processed by Stripe; we do not store card numbers), uploaded logo and branding preferences, contact details you add to your address book, and the contents of any support ticket or issue report you send us.
When you access the Service, we automatically collect your IP address, browser type and version, pages visited and features used, timestamps of your activity, and device information.
When you create an account, we store with that account any advertising campaign parameters and ad click identifiers that were on the link you arrived on (for example utm_* values and click IDs such as gclid, gbraid, wbraid, fbclid or msclkid), so we can attribute the signup to our own advertising.
Files, messages, and documents you transmit through the Service are encrypted at rest and protected by access controls and audit logging. Some workflows are processed by Vukorix systems so that features such as PDF rendering, E-Sign preparation, audit-pack generation, malware scanning, scanning for sensitive identifiers such as a possible Tax File Number, and delivery can work. Those features require server-side access to the content. Optional Private/end-to-end-style modes, where offered, provide additional recipient-side access isolation. We do not claim that every Vukorix workflow is fully isolated from, or unreadable by, Vukorix systems. Metadata associated with your content (such as file names, sizes, and expiration dates) is stored to operate the Service.
You can choose to connect a Google Drive account to Vukorix. If you do, we store the email address of that Google account, the access Google grants to Vukorix (encrypted at rest), and the identifiers and names of the files and folders Vukorix creates in your drive or that you pick. Vukorix can reach only the files you pick and the files it creates in its own "Vukorix" folder; it never asks for access to your whole drive.
A file you pick is copied into the Service and scanned like any other upload. When a document you sent for signature is completed and automatic saving is on, a copy of the signed PDF and its audit pack is saved into your drive; the originals stay in Vukorix as the record. Your organisation's owner and administrators can see which Google account you connected and can disconnect it, and the owner is told if that account is not on your work email domain. When you disconnect, we delete the stored access straight away. You can also remove Vukorix's access at any time in your Google account settings.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use it only to provide these features. We do not use it for advertising, we do not sell it, we do not use it to train artificial intelligence models, and no one at Osmicro reads it unless you ask us to, it is needed for security, or the law requires it.
We use your personal information to provide, maintain, and improve the Service, process transactions and manage your subscription, send you transactional emails (account verification, password resets, share notifications, signature requests), monitor and protect the security of the Service, comply with legal obligations, and respond to support requests.
We do not use your personal information to target advertising to you, and we never sell it. We do measure how well our own advertising works (see section 9).
Vukorix is offered to customers in Australia and this policy is written around Australian law. Someone you send a document to may be anywhere, and if you are in the European Economic Area our legal basis for processing your personal information is contract performance (to provide the Service you signed up for), legitimate interests (to maintain security and improve the Service), consent (where you have opted in to optional communications), and legal obligation (where required by law).
We do not sell, rent, or trade your personal information, and we never disclose it for another organisation's marketing.
We use a small number of service providers to operate the Service. Each one receives only what it needs for its function. All of them are based outside Australia. Section 11 sets out what each receives and where. We may also disclose information to law enforcement or a regulatory authority where we are required or authorised by law to do so.
When you share content with others through the Service (secure shares, file requests, exchanges, or e-signatures), the recipients you designate will receive access to that content as intended.
Your account and your documents are stored on servers located in Australia (Sydney). Some processing is carried out by overseas service providers (see section 11).
Our security measures include:
No method of transmission or storage is completely secure, and we do not claim otherwise. We maintain a documented response process for suspected data breaches.
Because documents sent through Vukorix can contain tax file numbers, we are a file number recipient under section 11 of the Privacy Act 1988 (Cth), and the Notifiable Data Breaches scheme in Part IIIC of that Act applies to us by law wherever a breach involves tax file number information: we will assess the breach and, where it is likely to result in serious harm, notify the affected individuals and the Office of the Australian Information Commissioner. For a breach that does not involve tax file number information we apply the same process and the same notification threshold as a commitment under this policy.
We keep personal information only for as long as we need it, and destroy or de-identify it when we no longer do. The periods we apply are:
| What | How long |
|---|---|
| Secure shares | Destroyed at expiry or when the view limit is reached, whichever comes first. A record of the delivery is kept, including the file names and the IP address and browser of whoever opened it, so you can prove the share happened. |
| File requests that expired | Kept until you delete them if anything was received: a file, a completed form, a secure note or the recipient's submission. Only an expired request that received nothing is deleted. A record of the request is kept (who it was for, whether and when they submitted, and the IP address they submitted from), so you can show what was asked and what happened. |
| File requests you completed or cancelled | Kept until you delete them. Expiry ends the recipient's access; it does not delete your copy. The record includes when the client submitted and the IP address they submitted from. |
| Exchanges | Kept until you delete them. The record includes when the recipient first opened the exchange and the IP address they opened from. |
| Private mode | For shares, file requests and exchanges sent in Private mode, we record the times but never the IP address of the person who opened or submitted. |
| Completed form submissions | Kept until you delete them. The answers and the completed PDF stay with the request or exchange they were submitted to. |
| Audit logs | 2 years (730 days). The signing audit trail of an E-Sign document is part of the document and is kept with it. |
| Sign-in attempts and link-verification attempts | 30 days. |
| Malware scan records | 90 days. |
| Queued email (including the message body we sent) | Body erased 30 days after sending; the record deleted at 90 days. |
When you delete your account, your account record and the content linked to it are removed immediately. Files are removed from our storage within approximately 38 days, which is the period our clean-up process holds a file aside before erasing it so that an accidental deletion can be reversed. A small number of records are kept beyond this where we need them to detect fraud or investigate a security incident, or where the law requires it, for example an audit entry recording that an account was deleted.
We give you the following two rights as a binding commitment under this policy, on the same terms Australian Privacy Principles 12 and 13 require of a business the Privacy Act covers. Neither depends on where you live, or on whether you hold a Vukorix account:
If we refuse an access or correction request, we will tell you in writing, give our reasons, and explain how to complain.
Beyond those rights, account owners can export their organisation's data from Settings and can delete the account. If you are a team member rather than the account owner, email us and we will handle your request directly. Note that deleting your individual access does not delete your organisation's documents, which belong to the organisation.
To make any request, contact [email protected]. We aim to acknowledge within 5 business days and respond within 30 days.
Essential cookies. We use cookies that are strictly necessary to operate the Service, including session cookies for authentication and CSRF protection tokens. These are always active and cannot be switched off.
Analytics and advertising. We use Google Analytics and Google Ads to understand how visitors find and sign up for the Service and to measure the effectiveness of our advertising. These tools run under Google Consent Mode with analytics and advertising consent set to denied by default. While consent is denied, no analytics or advertising cookies are stored on your device, and only limited, aggregated, cookieless measurement signals are shared with Google. Where you have given consent (for example through our marketing website), these tools may also set analytics or advertising cookies. If you have given that consent, we may also load Meta (Facebook) measurement code on our marketing website to record a page view, and we tell Meta (Facebook) and Reddit when a sign-up is completed so that we can measure the advertising we buy on those platforms. Sign-up measurement code is loaded only on the page that confirms your sign-up. All of this Meta and Reddit measurement runs only with your consent, and it is never loaded if your browser sends a Global Privacy Control signal. We never send personal information (such as your name, email address, phone number, document names, or file contents) to any of these tools. You can manage or block cookies through your browser settings; blocking essential cookies will prevent the Service from working.
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
Your documents are stored in Australia, but running the Service means a small number of overseas providers handle some of your information. We tell you which countries they are in because you are entitled to know. We apply the standard of Australian Privacy Principle 8 to those disclosures: before personal information goes to a provider outside Australia we take reasonable steps to satisfy ourselves it will be handled consistently with the Australian Privacy Principles, and we accept responsibility to you for what they do with it. Every provider below is in the United States.
| Provider | What it handles |
|---|---|
| Postmark | Sends our email. Receives the recipient's name and email address, and the subject line and body of the message. For completed e-signature workflows only, it also receives a signature audit pack PDF containing the document title, signer names and email addresses, timestamps, IP addresses and a cryptographic hash of the signed document. We do not attach your documents to email. |
| Stripe | Processes payments. Receives your name, email address and billing details. |
| Twilio | Sends verification codes by SMS. Receives the mobile number and the message. |
| Anthropic | Reads a PDF form template you upload to Smart Forms, when that PDF has no built-in form fields, so we can work out where the fields belong. This applies to templates you upload, not to documents your clients send you. |
| OpenAI | Powers the in-app help assistant. Receives your question and the recent conversation. |
| GitHub | Receives an issue report if you choose to send one, including what you wrote in it. |
| DigitalOcean | Hosts the Service and stores your documents, in its Sydney, Australia data centre. |
| Cloudflare | Sits in front of the Service to filter attacks. Traffic passes through it in transit; it does not store your documents. |
| Analytics and advertising measurement (see section 9), and sign-in if you use a Google account. Microsoft receives the same if you sign in with a Microsoft account. If you connect a Google Drive (section 2.4), the copies you choose to save there, and the automatic copies of your signed documents, are stored by Google in your own Google account under Google's terms. | |
| Meta (Facebook) | Advertising measurement only, and only with your consent: a page view on our marketing website, and a signal that a sign-up was completed (see section 9). No personal information. |
| Advertising measurement only, and only with your consent: a signal that a sign-up was completed (see section 9). No personal information. |
Automatic scanning for sensitive identifiers, such as a possible Tax File Number, runs entirely on our own servers in Australia. No document is sent overseas for that purpose.
On the two AI providers. Both Anthropic and OpenAI are used under their standard commercial API terms, which state that data sent through the API is not used to train their models. OpenAI additionally retains API data for up to 30 days for abuse monitoring. We do not opt in to any data-sharing arrangement with either.
We use each of these providers under its standard commercial terms, which include its data-processing commitments, and we remain accountable to you for how your information is handled.
The Service may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to read their privacy policies.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 14 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.
If you think we have mishandled your personal information, tell us and we will deal with it. Below is not just how to complain but how we will handle it, because a complaints process you cannot see the shape of is not a real one.
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Osmicro Networks Pty Ltd
Privacy Officer
Email: [email protected]
Website: vukorix.com.au
If you are not satisfied with our response, section 14 sets out how to escalate and which regulators can consider which kinds of complaint.