01Who this policy covers
ISOCheck is a Grey Meta service for Australian businesses. In this policy, “we”, “us” and “our” refer to Grey Meta as the provider of ISOCheck. This policy covers the ISOCheck website, business workspace, assessments and related support. Contact info@greymeta.com.au for privacy enquiries or a copy of this policy.
Your Grey Meta and ISOCheck accounts use a shared identity and business profile. This policy describes ISOCheck’s use of those records; a separate service you choose may have its own privacy notice.
02Information we collect
- Account and team details: names, work email addresses, mobile numbers, business details, account identifiers, roles, invitations and verification records.
- Assessment details: your scope, selected standards, location or jurisdiction, organisation profile, submitted evidence, findings, corrective actions and review history.
- Payment records: checkout references, amounts, payment status and related correspondence. Card details are entered into Stripe’s hosted checkout; ISOCheck does not store full card numbers or card security codes.
- Service information: support messages, session information, request and security logs, and AI model, usage and processing records. Hosting providers may process IP addresses, browser details and request times to operate and protect the site.
We collect information from you when you register, use the workspace, submit evidence or contact us. We also receive information from your business’s authorised users, the shared Grey Meta profile, and our authentication and payment providers.
Account creation requires contact details and verification. Assessments require scope and readable evidence. You can browse public pages without an account; if you withhold information needed for a service, we may be unable to provide it.
03Documents and information about other people
For assessment uploads, ISOCheck stores the original file you submit in a private, encrypted and virus-scanned location, and extracts its readable text when your assessment starts. Scanned documents and photographs are transcribed by an AI provider at that point so they can be assessed. Originals and extracted text are held only for the retention period you choose, and the text may appear as short quotations in your report.
You choose how long we keep it. Each assessment has a retention setting, from 30 days to seven years, which you can change at any time before the documents are removed. The clock starts when the assessment finishes, not when you order it, so nothing is removed while work is in progress or awaiting consultant review. When the period ends we delete both the original files and the extracted text, and record the date of removal on the assessment.
Your report is not deleted on that schedule. It is the service you paid for, and it remains available in your workspace. Reports quote short excerpts of your evidence to support each finding, so those excerpts remain in the report after the underlying documents are removed. Ask us if you want an assessment and its report deleted entirely.
Only submit evidence you are entitled to share. Remove unnecessary names, signatures, contact details and identifying information before uploading. Do not submit passwords, access keys, payment card details, government identifiers or identifiable medical information. If sensitive information is essential to your assessment, contact us to agree a suitable process before uploading it.
You are responsible for giving relevant notices and obtaining any permissions required to share another person’s information. A business account is a shared workspace: its authorised members can access records according to their access permissions.
04How we use information
We use information to create and verify accounts, manage business access, prepare and review assessments, process payments, provide reports and corrective-action tools, answer support requests, investigate errors or misuse, and meet applicable legal obligations.
Assessment evidence and relevant organisation details are sent through Vercel AI Gateway to the AI providers used for the assessment, currently OpenAI and Anthropic. The AI generates and checks findings against the supplied criteria. Authorised Grey Meta staff may review evidence and outputs for delivery, support and quality checks. See our AI and Acceptable Use Policy.
The ISOCheck application does not run model training on your evidence. Processing by external AI providers is governed by their service arrangements and the configured routing. This is not a promise of zero retention by every provider. Contact us before submission if you need particular data-location, retention or contractual restrictions.
06Security and retention
ISOCheck uses authenticated access, business-account permission checks and private server-side data operations. Access to unpublished reports is restricted. No online service can guarantee absolute security; protect your credentials and tell us promptly if you suspect unauthorised access.
We retain account and assessment records for as long as reasonably needed to provide the service, maintain an assessment history, resolve disputes and meet legal or accounting obligations. Retention depends on the record and purpose; we do not promise a single deletion period for all data. Provider logs and backups may have separate retention periods.
You can request account closure or deletion by email. We will assess the request, verify authority and explain any records that must be kept. Deleting or replacing a draft document does not necessarily remove quotations or records already included in a submitted assessment, report or backup. Download records you need before asking to close a workspace.
07Access, correction and complaints
Contact info@greymeta.com.au to request access to or correction of your personal information, ask about retention or overseas processing, or raise a privacy complaint. Include enough information to identify your account and the issue, but do not email passwords or unnecessary identity documents. We may need to verify your identity or authority to act for the business.
We will investigate your concern and explain our response and proposed resolution. We aim to respond to privacy complaints within 30 days and will let you know if more time is needed. Where an access or deletion request cannot be fulfilled, we will explain why, subject to applicable law.
If your concern remains unresolved, you can seek guidance or lodge an eligible complaint with the Office of the Australian Information Commissioner. Applicable privacy rights are not limited by this policy.
08Cookies and policy changes
Read the Cookie Policy for details about sign-in cookies and browser controls. We update this policy when our practices change and show the revision date on this page. Where a material change requires a further notice or consent, we will provide it before the new use where required.
09Who operates this service
ISOCheck is operated by Grey Meta, trading as Grey Meta, ABN 92 917 977 661. This is the supplier identified on ISOCheck tax invoices and the entity responsible for this policy.