Version 2026-08 · August 2026
Vortrek provides travel risk assessment software to users. This policy explains how we handle personal information in that role, consistent with the Australian Privacy Principles.
To generate and deliver assessments and briefings, to distribute and record acknowledgements, to maintain a defensible audit trail, to support and secure the Service, and to bill your organisation.
As a privacy and security consideration, Vortrek does not store information about individual activities beyond what is necessary to deliver the Service and maintain the audit trail described above.
Assessment content is produced with assistance from third-party AI models. Data sent to those models is de-identified wherever practicable: traveller names, staff IDs, contact details and other personal identifiers are stripped, and only itinerary, destination and role-context information is sent. Output is decision-support material and is reviewed by your organisation before use.
De-identification reduces but does not eliminate risk. Once data reaches a third-party provider, how it is handled, logged or retained is limited by that provider's own capabilities and terms, which we do not control. Do not enter personal information into free-text fields beyond what the assessment requires.
We share personal information only with sub-processors that operate the Service, and where required by law. We do not sell personal information. Our current sub-processors are:
We will publish an updated list before adding a sub-processor that materially changes how your data is handled.
Your account, traveller and assessment records are hosted in Australia. Some sub-processors — in particular AI model, email and payment providers — process limited data overseas, including in the United States and the European Union. We require contractual safeguards where that occurs and send de-identified data where the provider's function allows.
Data is encrypted in transit and at rest, access is scoped per organisation, multi-factor authentication is available and administrative actions are audit-logged.
Records are retained for your organisation's configured retention period where one is set, and otherwise until you delete them or close your account. A legal hold suspends deletion. Deleted records are purged on the scheduled daily retention run after a 30-day recovery window. Deleting your organisation's account triggers deletion of its records within 30 days, other than data we must keep for legal, tax or audit obligations. Backups age out within 30 days.
Individuals may request access to, or correction of, their personal information via their organisation's administrator or by contacting us at support@vortrek.com.au.
Updates are published with a new version identifier and re-acceptance is requested where the change is material.