Privacy Policy

Last updated: 27 September 2026

At BorderProof, we take privacy seriously. We are committed to handling your personal information responsibly and in accordance with applicable privacy laws.

1. Who We Are

BorderProof (our platform, BorderProof) is operated by BorderProof Pty Ltd (ABN 33 698 548 088) (we, us, our). While making our platform available and conducting our business we collect, store, use and disclose personal information. This policy explains what personal information we collect, why we collect it, and how we handle it. You can reach us about privacy at privacy@borderproof.com.

2. Which Privacy Laws Apply

BorderProof is an Australian business and handles personal information (a term we use interchangeably with personal data in this policy) in accordance with our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles incorporated in that Act.

Because our platform is available globally, privacy laws of other jurisdictions may apply to us and/or the personal information that we collect depending on where our users are located. This may include (without limitation) the following, as amended from time to time:

  • EU General Data Protection Regulation (for users in the EU and EEA, including Germany, the Netherlands, Spain and France).
  • UK GDPR and Data Protection Act 2018.
  • United States state privacy laws, including the California Consumer Privacy Act (CCPA/CPRA).
  • Canada's PIPEDA and Quebec's Law 25.
  • Japan's Act on the Protection of Personal Information (APPI).
  • Singapore's Personal Data Protection Act (PDPA).

Our Privacy Policy sets out how we handle personal information or personal data and your rights depending on where you are located.

3. What Personal Information Do You Collect and How?

What we collect

We may collect and hold the following types of personal information about users, visitors to our website, and individuals who interact with us and our platform.

  • Identity information. This includes information such as your name, age and date of birth, nationalities.
  • Information relevant to visa requirements. This may include intended purpose (such as work, study, or investment abroad), destination preferences, occupation, job title, industry, and years of experience, current employer, qualifications, employment status and history, current salary, education status and history, English proficiency, marital status, spouse or partner nationality, number of dependants, and financial information including savings ranges and whether you can demonstrate maintenance of funds and other similar information relevant to visa requirements.
  • Technical information. We may collect technical and session usage data, including IP address, browser type, device, and page views.
  • Other information. We may also collect information you choose to provide during communications with us, including emails, calls, meetings or forms submitted through our website, as well as information provided through online interactions such as enquiries, live chat or social media messages.

How we collect it

We collect the information directly from you, this includes when you engage with our platform, fill out forms, answer questionnaires, upload documents or information, create an account, or otherwise provide us information.

Where you use certain features of our platform before creating an account, information you enter may be collected and stored against a temporary session. While this information is not linked to your name or contact details, it may still constitute personal information where it can be used to identify you. Where that is the case, it is handled in accordance with this Privacy Policy.

While providing information is voluntary and some features of our platform can be accessed without providing certain information, others depend on what you provide — and we may not be able to deliver those features if you do not supply the relevant information or you withdraw your consent.

4. Cookies and Tracking

We use cookies and similar technologies to operate the platform, remember your preferences, and understand how the platform is used. These include strictly necessary cookies (always on), and analytics and functionality cookies (for example Google Analytics and HubSpot), which we only set with your consent where the law requires it (including in the EU and UK). You can manage your preferences at any time through the Cookie Settings link on our website or your browser settings. Disabling non-essential cookies will not prevent you from using the platform.

5. Sensitive Information

There may be times when some information we collect may constitute sensitive information under applicable privacy laws. We only collect sensitive information where it is reasonably necessary for our platform's functions and with your consent, which we seek at the point of collection. We handle sensitive information with the same care as other personal information.

6. How We Use the Information

We do not sell personal information. We may use personal information for the following purposes.

  • To deliver and operate our platform and our business. This may include providing you with outputs such as visa discovery results or other summaries, and generally operating and maintaining the platform and your account.
  • To improve and secure our platform. This may include product development, research, insights and analysis purposes, and benchmarking, monitoring, debugging, fraud and abuse prevention.
  • To communicate with users of our platform. This includes communications about our platform, accounts, and/or material changes to this policy.
  • For administrative purposes. This includes for our record-keeping and planning purposes.
  • For legal and regulatory purposes. This includes to comply with legal and regulatory obligations under applicable laws.
  • For other purposes that we disclose to you at the point of collection.

Where required by applicable privacy laws (including the GDPR and UK GDPR), we process your personal information on the following legal bases:

  • with your consent;
  • performance of our agreement with you (delivering the platform, your account, and outputs you request);
  • our legitimate interests (improving and securing the platform, analytics, and business administration), balanced against your rights;
  • your consent, which you may withdraw at any time; and compliance with our legal obligations.

We will only use or disclose personal information for a secondary purpose if that secondary purpose is directly related to the primary purpose for which we collected it, and you would reasonably expect it in the circumstances, or if permitted by applicable law.

7. Sharing and Disclosure

We do not share your personal information to third parties without your permission, except as provided in this clause. This includes that we do not pass your information to immigration authorities, employers, or law firms unless we are required to do so by any applicable law, regulation or court order and/or you specifically ask us to.

We may share personal information with our third party providers, including sub-processors and service providers. This includes parties who help us run the platform — for example, our encrypted cloud storage provider. We take reasonable steps to ensure they handle data consistently with applicable laws. Examples of our current providers include: Google (Gemini AI), HubSpot, Google Analytics, PostHog, and LaunchDarkly. We take reasonable steps to ensure they handle data consistently with applicable privacy laws. However, their processing and storage of your personal information may be subject to their own policies.

8. Marketing Communications

With your consent, or otherwise where permitted by applicable law (including the Spam Act 2003 (Cth)), we may send you marketing communications, including about platform features, new visa pathways, and insights. Every marketing email includes an unsubscribe link, and you can opt out at any time without affecting your use of the platform. You also have the right to object to direct marketing.

9. Where Is My Information Stored and What Security Measures Are There?

Your documents and personal information are stored on encrypted servers in the United States of America, managed by reputable infrastructure providers.

We take reasonable steps to ensure the security and integrity of personal information we collect and hold. Every document you upload to our platform is encrypted the moment it leaves your device — in transit and at rest. That means even if someone intercepted the connection, they would see nothing readable.

10. AI and Privacy

Our terms of service explain how we may use automated and artificial intelligence services, including rules-based engines and generative AI, in our platform. Please refer to those for that detail.

AI and your information

We may use AI to process the personal information you provide to provide our platform and its features and functionalities to you, including to generate and provide outputs, results and information. During this process, AI systems may read and extract your information, check it against information in our platform, and may generate new information for you to consider.

How this may affect you

While the AI is not making decisions for you, you acknowledge that its outputs may influence decisions you make. You are responsible for reviewing and verifying all results and outputs and for any decisions you ultimately make.

In the ordinary course of operating the platform, no human at BorderProof reads your documents during any process that uses AI. Limited human access may occur where necessary for support requests, security, debugging, or abuse or misuse investigations. The AI processes your information and generates your results, and that's it.

Training and your personal information

We take steps to limit the use of your data for AI training purposes (for example using a paid tier where we can opt out of training), but we cannot guarantee that third-party AI providers we rely on will not process your inputs as part of their own training or improvement processes. You should be mindful of this when uploading information into our platform.

11. How Long Do You Keep My Information For and Can I Delete It?

Retention by us

Personal information is retained only for as long as it remains necessary for the purposes for which it was collected, or as required by applicable laws and regulations as well as set out below.

Generally

Where you have an account on our platform, you can request deletion of your account and information at any time. As explained in our Terms, deletion takes effect after a 14-day cooling-off period, and some records are retained where the law requires (see below). There are instructions in your account on how to do so and you can also contact us to help you. Where you don't have an account, please contact us if you want us to delete your email address and any profile information you've provided.

Account deletion and retention

When your account is deleted, your personal information and uploaded documents are permanently removed from our systems, subject to the following:

  • Purchase records are retained for 7 years for tax and legal compliance reasons.
  • Aggregate data as described in our Terms derived from your use of the platform is not personal information and is not subject to deletion.
  • We cannot delete personal information held by third-party service providers — see section 7 above.

For full details on how to delete your account, cooling-off periods, and data export, please refer to our Terms.

12. What Are My Rights?

You have the right to contact us to:

  • confirm what personal information BorderProof holds about you and ask us to access it;
  • correct any inaccurate information;
  • delete your data in your account, or ask us to delete information where we are not required to retain it for the purposes that we collected it for and/or legal or compliance reasons.

In some other jurisdictions, such as the UK or EU GDPR, you may have additional rights, such as the right to:

  • download your data in a portable format; and
  • withdraw consent for any data processing, or object to certain processing, at any time.

To exercise any of these rights, email privacy@borderproof.com. We will respond as soon as reasonably practical (and in any case in accordance with our legal obligations).

13. Who Do I Contact If Something Goes Wrong?

If you have any concern about how your data has been handled — or if you believe there has been a security incident affecting your information — contact us immediately at privacy@borderproof.com.

We will acknowledge your concern promptly and respond as soon as reasonably practicable. In the event of a data breach that is likely to result in serious harm or risk to you, we will notify you and any relevant regulator without undue delay and within the timeframes required by applicable law (including the Notifiable Data Breaches scheme in Australia and the GDPR in the EU/UK).

14. International Data Transfers

General hosting

Wherever you are located, your personal information is stored in Australia, where BorderProof operates. Some processing happens outside Australia: in particular, when you use features powered by artificial intelligence, the information you provide for that feature is processed by our third-party AI providers in the United States. Wherever your information is stored or processed, we take reasonable steps to ensure it is protected to a standard consistent with the privacy law that applies to you.

Third parties

Third parties to whom we disclose your information, as described in section 7 above, may process your personal information in locations outside Australia, including locations determined by those providers under their own terms.

Australia

For Australian residents, we take reasonable steps to ensure that overseas service providers who store or handle your personal information are bound by obligations consistent with the Australian Privacy Principles.

EU and UK

If you are in the EU, EEA or UK, your personal data is transferred to Australia, and — when you use AI-powered features — to our providers in the United States. These transfers are made using safeguards such as the European Commission's Standard Contractual Clauses (with the UK Addendum or International Data Transfer Agreement where required), or another lawful transfer mechanism.

15. Complaints and Your Rights, Depending on Where You Are

If you have a concern, please contact us first at privacy@borderproof.com so we can try to resolve it. We would appreciate the chance to deal with your concerns.

  • Australia (Privacy Act / APPs): You can ask to access and correct your personal information. You can raise a concern with us and then with the Office of the Australian Information Commissioner (OAIC).
  • EU/EEA (GDPR): You can ask to access, correct, delete, restrict or port your data, object to certain processing, and withdraw consent. You can complain to your local Data Protection Authority.
  • United Kingdom (UK GDPR): The same core rights apply. You can complain to the Information Commissioner's Office (ICO).
  • United States: Privacy rights in the US vary by state. Depending on where you live and whether your state has a consumer privacy law, you may have rights to access, delete and correct your personal information and to opt out of its ‘sale’ or ‘sharing.’ BorderProof does not sell your personal information. Some analytics or advertising technologies may constitute ‘sharing’ for cross-context behavioural advertising under the CPRA; where that applies, you can opt out via Cookie Settings or by contacting us. To exercise any rights you have, or to raise a concern, contact us at privacy@borderproof.com; California residents can also complain to the California Privacy Protection Agency, and residents of other states to their State Attorney General.
  • Canada (PIPEDA / Quebec Law 25): You can ask to access and correct your data and withdraw consent. You can complain to the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information du Québec.
  • Japan (APPI): You can ask us to access, correct, or stop using your personal information, and complain to the Personal Information Protection Commission (PPC).
  • Singapore (PDPA): You can ask to access and correct your data and withdraw consent. You can complain to the Personal Data Protection Commission (PDPC).
  • Elsewhere: If you are located in a country not listed above, you may still have privacy rights under your local law. Contact us and we will respond in accordance with the law that applies to you.

How to exercise your rights

To make any request above, email us at privacy@borderproof.com. We may need to verify your identity before acting. We will respond within the timeframe required by the law that applies to you, and in any case as soon as reasonably practicable.

16. Changes to This Policy

We will update this page when our practices change. Material changes will be notified by email to account holders. The date at the top of this policy indicates when it was last updated.

17. Contact Us

If you have a question this page doesn't answer, email us at privacy@borderproof.com. A real person will respond.