Privacy Policy
Effective date: 23 May 2026Last updated: 5 July 2026
Go Compani Pty Ltd (ABN 63 701 137 279, ACN 701 137 279), a company registered in Australia. This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you use our platforms, our website, and related services (collectively, the “Service”).
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Who this policy applies to
This policy covers personal information about:
Account holders — administrators, super admins, and end users who sign in to our platforms on behalf of an organisation.
Invited team members who receive an email invitation to join an organisation.
Vendor contacts — people at third-party service providers whom an organisation's admin contacts through our platforms (for example, to complete a privacy questionnaire).
Website visitors who interact with our public pages.
If your organisation uses our platforms, your organisation is the controller of information it puts into the platform, and our platform acts as a processor on its behalf. This policy describes our own practices.
2. What our platforms do
Visibility is a B2B privacy-compliance and cyber-risk platform. It helps organisations:
maintain an inventory of the apps and services they use;
review and score vendor privacy policies and terms of service (with AI assistance) to surface where data is stored, who it's shared with, and how long it's retained;
align with recognised technology safety, privacy and security frameworks; and
send privacy questionnaires to vendors and track their responses.
Ticket is a B2B Ticketing and Device Management platform. It helps organisations:
Capture, review and maintain inventory of devices they use;
Capture, review and update tickets;
send updates to requestors and track their responses.
Incident is a B2B Incident Management platform. It helps organisations:
Capture, develop, review and maintain details about incidents;
Capture, review and update contacts;
Send communications to contacts.
3. Information we collect
3.1 Information you give us
Account details: full name, work email address, job role, profile image (if provided), and a hashed password (for email/password accounts).
Multi-factor authentication: an OTP secret stored on our servers so we can verify your one-time codes.
Passkeys: if you set up a passkey, we store its public key and credential identifier so we can verify your future sign-ins. The passkey's private key never leaves your device — we cannot see it.
Organisation details: organisation name, primary domain, size, country and industry.
Vendor contact details: names, email addresses and roles of people you nominate at third-party service providers, plus their responses to questionnaires you send them.
Support and correspondence: information you provide when you contact us.
3.2 Information we collect automatically
Authentication data: IP address (used for rate limiting and abuse prevention), and identifiers from your identity provider (e.g. a Microsoft Entra Object ID or Google subject ID) if you use Single Sign-On.
3.3 Vendor contacts and questionnaire responses
If an administrator at one of our customers asks a service provider to complete a questionnaire, we will hold the contact's name, email address and role, and any answers they submit, solely to deliver that questionnaire and record the response on behalf of our customer.
If you are completing a questionnaire about your own organisation:
Who sees your answers. Your responses are recorded against the service being reviewed and are visible to administrators at the customer who requested them. We do not show them to our other customers.
How they are used. Your answers are used to assess that service against privacy, security and technology-safety frameworks. As described in Section 4, the text is analysed with AI assistance — we strip identifiers before sending it, and we never send the name or email fields we hold for vendor contacts.
What we do not do. We do not use your responses to market to you, and we do not sell them.
Correcting or removing your details. If you want the contact details we hold for you removed, email us at the address in Section 11. Your rights are set out in Section 9, and retention in Section 7.
4. How we use information
We use personal information to:
create and secure your account, including MFA;
provide the Service and the features described in Section 2;
analyse the privacy policies and terms of the services you track, and the questionnaire answers vendors submit, using AI assistance. Before any such content is sent to our AI sub-processor we automatically remove direct contact identifiers (email addresses and phone numbers), and we never send the name or email fields we hold for your users or your vendor contacts;
send notifications to administrators when relevant changes are detected;
send transactional emails (verification, invitations, password resets, alerts, billing);
bill subscriptions and manage plan tiers;
investigate security incidents; and
comply with our legal obligations.
We rely on the following legal bases (where relevant): performance of a contract with your organisation, our legitimate interests in operating and securing the Service, your consent (e.g. when you connect an identity provider), and compliance with law.
We do not use your personal information for advertising, and we do not sell personal information.
5. Sub-processors and disclosures
We share personal information only with the following categories of recipients, and only as needed to run the Service:
CategoryPurposeData shared
Cloud infrastructure — Google Cloud Platform (application hosting and compute) and a managed database providerRunning the platform and storing your data. Your data at rest — including uploaded files — is stored in our managed database; application compute runs on Google Cloud Platform. All data is hosted in Sydney, Australia.
Third-party AI provider - Analysing incidents, documents, policies, terms and vendor questionnaire answers. Before it is sent we automatically strip direct contact identifiers (email addresses and phone numbers), and we never include your account password, MFA secret, sign-in identifiers, or the name and email fields we hold for your users or your vendor contacts.
Payments provider — Stripe - Subscription billing and payment processing. Billing contact email, plan information and payment details. Card details are handled directly by Stripe; we do not store full card numbers.
Transactional email provider — SMTP2GO (Australian region)Sending verification, invitation, alert and billing emailsRecipient email address and the email contentsIdentity providers — Microsoft Entra ID and Google (plus any Single Sign-On provider your organisation chooses to configure).
We have agreements in place with these providers that require them to protect your information. Some of these providers process data outside Australia (for example, in the United States or the European Union) under their own contractual and technical safeguards.
We may also disclose information where required by law, to enforce our terms, or to protect the rights, property or safety of users, the public or Visibility.
6. Cookies
We use a single strictly-necessary cookie (connect.sid) to keep you signed in. It is HttpOnly,SameSite=Lax, and Secure in production. We do not use marketing, advertising or third-party tracking cookies.
7. Data retention
We keep personal information only for as long as we need it:
Account data — for as long as your account is active, then for a reasonable period afterwards for audit, dispute resolution and legal compliance.
Billing and tax records — Stripe, our payments provider, is the system of record for your invoices, payments and refunds, and holds them under its own retention policy. We do not keep a copy of your invoices in Visibility. Records of this kind generally need to be kept for 7 years under Australian tax and accounting law; that obligation is met in Stripe, not here. Please download any invoices you need before your organisation is deleted — afterwards we hold no identifier with which to locate your Stripe record on your behalf.
Sign-in records — we log every sign-in attempt, successful or not, so we can investigate account compromise and unusual access. Each record holds the email address used, the IP address it came from, the country we work out from it, your browser's user-agent string, and whether the attempt succeeded. We keep these for 90 days and then delete them automatically.
Administrative activity records — most in-app activity records are deleted after 30 days. A small set recording irreversible administrative actions — an account or organisation being suspended, deleted or merged — is kept indefinitely so the audit trail stays complete. When the person involved is deleted, those records are no longer linked to their account.
Consent records — when you accept our Terms of Use or a privacy disclaimer we keep a permanent record of that acceptance: your name and email address, your organisation's name and domain, your role, the exact wording you agreed to, the date and time, and the IP address and browser you used. This is a legal record of an agreement, so we keep it even after your account is deleted, as evidence that the agreement was made. We unlink it from your deleted account, but we do not remove the record itself.
If a paid plan lapses — you cancel, or a payment fails — your organisation moves onto our Free plan for 30 days. You and your team keep signing in and working as normal, within the Free plan's limits.
If a free trial ends, or that 30-day Free-plan window runs out, your organisation moves to a read-only state: you and your team can still sign in and view your existing data, but adding, re-analysing or changing services is paused until you upgrade or resubscribe. We'll email your administrators a reminder before any access is removed. Upgrading or resubscribing at any point restores full access.
If the plan stays expired for 60 continuous days, your organisation is hidden and sign-in is blocked, but your data is not deleted straight away. We keep it recoverable for a further 30 days. If you resubscribe within that 30-day recovery window — or ask us to restore your organisation — everything is reinstated exactly as you left it. Only after the 30-day recovery window has passed do we permanently delete your organisation-specific data, including your account, your team's accounts and your service portfolio.
Counting from the day your plan ends, that is about 90 days if a free trial expired, and about 120 days if a paid subscription lapsed — the extra 30 being the Free-plan window described above.
This deletion does not affect our shared service catalogue (the privacy and terms-of-service assessments of third-party services), which is not specific to any organisation and is retained.
It also does not affect vendor records. Where your administrators entered a vendor contact's name, email address, phone number or role, or that contact answered a security questionnaire, those details are held against the vendor rather than against your organisation, so they are kept after your organisation is deleted. They are visible only to our own platform administrators — we do not show vendor contact details to our other customers. If you are a vendor contact and want your details removed, email us at the address in Section 11.
If you delete your own account. You can ask us to delete your account from your profile page. We schedule it 7 days ahead and email you to confirm; you can cancel at any time during those 7 days. If you are the last administrator of your organisation, we won't let you delete your own account on its own — promote another administrator first, or ask us to close the whole organisation.
What "delete" means here. When we delete a person, we de-identify rather than erase every trace. We permanently remove the identifying and security material we hold — name, email address, profile photo, job role, password, multi-factor secret, passkeys and single sign-on identifiers — and we strip the account's role, its permissions and its access to any organisation, so it can no longer sign in or reach anything. We remove the email address, IP address and browser details from that account's sign-in records at the same time, rather than waiting for the 90-day window above. Sign-in attempts we were never able to match to an account — a mistyped address, for example — are not linked to you and are deleted on the normal 90-day cycle.
What remains is an anonymous placeholder that keeps our records structurally intact, so the administrative audit trail above still makes sense. This is one-way: once it is done we cannot work out who the account belonged to, and we cannot restore it.
When your organisation closes its account, we delete or de-identify personal information within a reasonable period, unless we are required to keep it by law.
8. Security
We take reasonable steps to protect personal information from misuse, loss and unauthorised access, including:
TLS encryption for data in transit;
AES-256-GCM encryption at rest for sensitive secrets (such as API keys, integration tokens and multi-factor secrets);
bcrypt password hashing and SHA-256 hashing of security tokens;
support for passkeys (WebAuthn) — a phishing-resistant sign-in method — and mandatory multi-factor authentication for email/password accounts;
rate limiting, CSRF protections and same-origin checks on mutating requests; and
role-based access controls (user, admin, enterprise admin, super admin).
No system is perfectly secure. If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme.
9. Your rights
You can:
Access the personal information we hold about you;
Correct information that is inaccurate or out of date (most account details can be updated in the app);
Delete your account (contact your organisation's administrator, or us if your administrator is unavailable);
Withdraw consent to optional integrations (e.g. disconnect an identity provider) at any time in the app; and
Complain about how we handle personal information.
To make a request, email us at the address in Section 11. We will respond within a reasonable time, normally within 30 days. If you are not satisfied with our response, you can lodge a complaint with the OAIC at www.oaic.gov.au.
10. Children and student information
Visibility is a tool for organisations and their staff. It is not designed for, or directed at, children, and we do not knowingly collect personal information directly from children. Customer organisations, including any educational institutions, must not enter student personal information into Our Platforms (such as student names, contact details or other identifiers). Visibility is not intended to hold student records and should not be used for that purpose.
11. Contact us
If you have questions about this policy or want to exercise your rights, contact us at:
Go Compani Pty Ltd
ABN 63 701 137 279
ACN 701 137 279)
Email: privacy@gocompani.com
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify account holders by email and by an in-app banner before the changes take effect. The “Last updated” date at the top shows when it most recently changed.
13. Governing law
This policy is governed by the laws of Queensland, Australia. Any dispute about it will be dealt with by the courts of Queensland.