Aristos ID

Privacy Policy

How Aristos ID collects, uses, and protects your personal information

Last updated: 4 October 2026

1. Our Commitment

Aristos ID is designed with privacy as a foundational principle. We comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Digital ID Act 2024 and its associated accreditation rules and data standards. This page explains what data we collect, why we collect it, and the control you have over it.

2. Data We Collect

We collect only the minimum data necessary to provide identity and authentication services:

  • Account information: Your name, email address, and optionally a phone number.
  • Authentication data: Password hash (never the plain-text password), TOTP secrets (encrypted), and WebAuthn public keys (cryptographic derivatives, not raw biometrics).
  • Session data: IP address, user agent, and session timestamps for security and audit purposes.
  • OAuth consent records: Which applications you have authorised and what data you shared with them.
  • Audit log entries: Records of actions taken on your account for security and compliance.

We do not collect:

  • Raw biometric data (fingerprints, face scans, iris patterns)
  • Browsing history or online behaviour profiles
  • Location tracking data
  • Marketing cookies or third-party tracking pixels

3. How We Use Your Data

Your data is used solely for:

  • Authenticating your identity when you log in
  • Authorising third-party applications you have explicitly approved
  • Securing your account against unauthorised access
  • Maintaining audit trails required by law
  • Providing account recovery if you lose access

We do not use your data for marketing, profiling, or tracking your online behaviour. We do not sell or share your data with third parties for commercial purposes.

4. Biometric Information

When you use biometric authentication (such as fingerprint or face unlock via WebAuthn), your device creates a cryptographic key pair. The private key never leaves your device's secure enclave. We only store the public key, which cannot be used to reconstruct your biometric data.

You can view and delete your registered biometric credentials at any time from your Privacy Dashboard. Deleting a credential permanently removes the associated public key.

5. Consent

When a third-party application requests access to your data, we require your express consent. This means:

  • You see exactly what data will be shared before approving
  • You can choose which optional data to share (data minimisation)
  • You must actively check a consent box — consent is never inferred
  • You can revoke consent at any time from your Privacy Dashboard

6. Data Retention

We retain your data only for as long as necessary:

  • Audit logs: 7 years (required by the Digital ID Act accreditation rules)
  • Session data: Until session expiry or you revoke the session
  • OAuth consents: Until you revoke consent or delete your account
  • Biometric credentials: Until you delete them or your account is deleted
  • Data exports: 7 days after generation, then automatically deleted

7. Your Rights

You have the right to:

  • Access — Download a copy of all your data from your Privacy Dashboard
  • Correct — Update your profile information at any time
  • Delete — Request permanent deletion of your account and all data
  • Revoke consent — Withdraw consent for any connected application
  • Manage sessions — View and revoke active sessions on any device
  • Manage biometrics — View and delete registered biometric credentials

To exercise these rights, visit your Privacy Dashboard.

8. Data Breach Response

If we become aware of a data breach that is likely to result in serious harm, we will:

  • Contain the breach and prevent further unauthorised access
  • Notify affected users as soon as practicable
  • Notify the Office of the Australian Information Commissioner (OAIC) where required
  • Take steps to prevent recurrence

9. Data Residency

All personal data is stored on servers located in Australia. Your data is subject to Australian law and is not transferred to overseas jurisdictions without your consent.

10. Security Measures

We implement industry-standard security measures including:

  • End-to-end TLS encryption for all data in transit
  • Argon2id password hashing (resistant to brute force and rainbow table attacks)
  • SHA-256 token hashing — plain-text tokens are never stored
  • Content Security Policy (CSP) with per-request nonces
  • CSRF protection on all forms
  • Rate limiting and brute force protection
  • Tamper-evident audit logging with hash chaining
  • Regular security audits and penetration testing

11. Contact

If you have questions about this Privacy Policy or how your data is handled, please contact us through your account's support channels.

This Privacy Policy is provided in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and the Digital ID Act 2024.