Skip to content
Pylon Digital

Security and data

Security and data residency for AI, apps and websites

Where does your firm's data go? When Pylon Digital builds and runs your systems, client data is stored in fully GDPR-compliant data centres, and we show you each AI provider's terms on model training before the build starts. This page covers where data is stored, encryption, access, backups, privacy, breach response and what to ask about insurance.

Last updated:

Illustration: where client data goes, and who can see it.

At a glance

Quick facts

The short version, for partners who need an answer before the detail. Each point is explained further down this page.

Where data is stored
Client data for the systems we build and run is stored in fully GDPR-compliant data centres.
Who has access
Your firm decides who uses each system. Pylon Digital's own access is scoped to what each system needs and listed in its run book.
Encryption
Encryption in transit and at rest is set for each system and recorded in its handover documentation.
Backups
For systems we host, backup frequency, retention and location are recorded in that system's run book.
AI model training
We show you each AI provider's terms on model training before the build starts, and switch on the settings it offers to keep client data out of it.
Breach response
If a system we run for you is involved in an incident, we tell your firm as soon as practicable and help you assess it.

Where is client data stored?

Client data for the systems we build and run is stored in fully GDPR-compliant data centres. Access is limited to the people and systems that need it, and your proposal sets out how your data is handled. For tools your firm licenses directly, such as a public AI business plan, the provider’s own terms apply.

How is our data encrypted?

Encryption protects data in two states: in transit, as it moves between your systems, your staff and ours, and at rest, where it is stored. Each system we build uses encrypted connections in transit and the storage encryption its hosting provider offers at rest, and the handover documentation records which.

Encryption in transit stops anyone intercepting data between a browser or system and the server. It is what the padlock in a browser’s address bar signals, and it matters just as much for connections between systems, such as a practice-management system sending figures to a weekly report. Encryption at rest protects stored data if a disk, database or backup is accessed outside normal controls.

Keys matter as much as the algorithm, because whoever controls the keys controls the data. Your handover documentation records who manages the keys for each system.

Who can access our data?

Access has two sides: the people in your firm who use a system, and the Pylon Digital people who build and run it. Your firm decides the first group. For the second, access is limited to what each system needs and listed in its run book.

  • Single sign-on. Where your systems support it, staff sign in with their existing work accounts, such as Microsoft 365, so access ends the day someone leaves the firm.
  • Least privilege. Connections get the narrowest access the job needs. Practice Reporting, for example, reads from your practice and accounting systems and never writes back to them, using read-only access wherever a system offers it.
  • Audit logs. AI agents record every action in a full audit log, and a person approves anything that leaves the firm. The exception is the After-hours Receptionist, which answers callers live from wording your firm has approved in advance and hands anything else to a person.

Do you follow the ACSC Essential Eight?

We use the Essential Eight as our reference point. We don’t describe our own controls as aligned without stating a maturity level, because alignment means little without one.

The Essential Eight is a baseline of eight mitigation strategies from the Australian Signals Directorate’s Australian Cyber Security Centre: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. ASD’s Essential Eight maturity model grades implementation from Maturity Level Zero to Maturity Level Three. When any provider says it is aligned, ask which level, for which strategies, and who checked.

How are backups and recovery handled?

Backups are what let a system recover from a failure, a mistake or a ransomware attack. For systems Pylon Digital hosts, the backup schedule, retention period and storage location are recorded in each system’s run book.

A backup only counts if it restores. Regular backups are one of the Essential Eight strategies for the same reason.

For tools your firm licenses directly, such as Microsoft 365 or a ChatGPT, Claude, Copilot or Gemini business plan, the provider’s own backup and retention terms apply, and they are worth checking separately.

How do you approach the Australian Privacy Principles?

Your firm’s privacy obligations stay with your firm, so each system’s handover documentation records what personal information it uses, where it is kept and who can see it. The Australian Privacy Principles (APPs) are the 13 principles in the Privacy Act 1988 (Cth) that govern how personal information is collected, used, disclosed, kept accurate and secured.

The APPs apply to Australian Government agencies and to organisations with annual turnover of more than $3 million, as well as some smaller businesses, such as private sector health service providers and businesses that trade in personal information (OAIC). Many professional firms are covered. The principles that matter most when a technology provider handles client information are:

  • APP 5, notification of collection: telling people what is collected about them and why.
  • APP 6, use or disclosure: using personal information for the purpose it was collected for, with limited exceptions.
  • APP 8, cross-border disclosure: the steps an entity must take before personal information is disclosed overseas.
  • APP 11, security: reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Since the 2024 amendments, those steps expressly include technical and organisational measures.

From 10 December 2026, under the Privacy and Other Legislation Amendment Act 2024, privacy policies must also explain when a computer program uses personal information to make, or help make, decisions that could reasonably be expected to significantly affect an individual’s rights or interests. That is relevant to any firm using AI in client-facing work. Each system’s handover documentation records what personal information it uses, where it is kept and who can see it, which helps your firm answer those questions. Our guide to AI and the Australian Privacy Principles covers each principle in plain English.

Do AI providers train on our data?

That depends on each provider’s terms, and you see them before anything is built. We check each model provider’s terms and settings, show them to you, switch on the settings it offers to keep client data out of training, and record them in the handover documentation.

Public AI tools depend on the plan and its settings. The business and consumer versions of the same product can handle training differently. For example, Anthropic states that by default it does not use inputs or outputs from its commercial Claude products to train its models, while its consumer plans have separate terms (Anthropic privacy centre, as at September 2026). AI Setup configures the admin controls and training opt-outs each provider offers, and sets the rules for staff in your firm’s AI usage policy. Our article on where ChatGPT stores your data explains the differences between plans.

For firms that cannot put client data into public tools, Private AI and knowledge assistants give staff chat and “ask our documents” search over precedents, policies and procedures. Private AI stores client data in fully GDPR-compliant data centres, and your firm chooses which documents it can search. Your agreement sets how long prompts and outputs are kept, and who can see them.

What happens if there is a data breach?

If we suspect an incident affecting client data, we tell affected clients as soon as practicable, work to contain it and share what we find in writing. Early notice matters because your firm may have its own obligations under the Notifiable Data Breaches scheme.

The Notifiable Data Breaches (NDB) scheme, in Part IIIC of the Privacy Act, has applied since 22 February 2018 to the organisations and agencies the Act covers. A breach is an eligible data breach when three things are true:

  1. Personal information is accessed or disclosed without authorisation, or lost.
  2. That is likely to result in serious harm to one or more individuals.
  3. Remedial action has not prevented the likely risk of serious harm.

An entity that suspects an eligible data breach must take all reasonable steps to complete an assessment within 30 days. Once it has reasonable grounds to believe one has occurred, it must notify the OAIC and the individuals at risk as soon as practicable. Where more than one entity holds the information, such as a firm and its technology provider, only one needs to notify; OAIC guidance suggests it is usually the entity with the most direct relationship with the affected individuals.

The rules are changing. On 31 August 2026, the Attorney-General’s Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, which proposes that entities notify the Commissioner of an eligible data breach within 72 hours of having reasonable grounds to believe one has occurred. Consultation closed on 18 September 2026; as at September 2026 it is a draft, not law.

What insurance should a technology provider hold?

Any provider that builds or runs systems holding client data should carry cover that matches the work, typically professional indemnity and cyber insurance. Ask which policies it holds and what they cover, and ask us the same on the discovery call.

Ask for certificates of currency before you sign. It is a reasonable request of any provider that will handle client data, and it confirms the cover is current and matches the work being done.

How can we get more detail?

Ask us directly. Book the free 45-minute discovery call through our contact page and tell us what your firm needs to see, whether that is answers to your own vendor security questionnaire, a list of sub-processors or a conversation with your IT provider, and we will tell you what we can provide.

The date at the top of this page shows when it last changed.

This is general information, not legal advice.

Questions

Frequently asked questions

Where is our data stored?

Client data for the systems we build and run is stored in fully GDPR-compliant data centres. Access is limited to the people and systems that need it, and your proposal sets out how your data is handled. For tools your firm licenses directly, such as some public AI plans, the provider's own terms decide where data is stored, so check them before setup.

Do AI providers train on our data?

It depends on each provider's terms. Before we build, we check each model provider's terms and settings, show them to you, switch on the settings it offers to keep client data out of training, and record them in the handover documentation. Public AI tools differ by plan: the business and consumer versions of the same product can treat training differently. That is why AI Setup includes configuring the admin controls and training opt-outs each provider offers.

Who at Pylon Digital can see our data?

Pylon Digital's access is limited to what each system needs to run and is listed in its run book. Your firm decides who inside the firm can use each system, with single sign-on where your systems support it, so access ends when someone leaves. AI agents log every action and wait for human approval before anything leaves the firm, except the After-hours Receptionist's live answers, which use wording your firm approves in advance.

What happens if there is a data breach involving our data?

If a system we run for you is involved, we tell your firm as soon as practicable and help you assess it, on the terms in your agreement. Under the Notifiable Data Breaches scheme, an entity must take reasonable steps to assess a suspected eligible data breach within 30 days and notify the OAIC and affected individuals as soon as practicable. Where a firm and its provider hold the same information, only one of them needs to notify.

Do you follow the Essential Eight?

We use it as our reference point, and we don't describe our own controls as aligned to the Essential Eight without stating a maturity level. The Essential Eight is the Australian Signals Directorate's set of eight baseline mitigation strategies, from patching and multi-factor authentication to regular backups. Each is graded from Maturity Level Zero to Maturity Level Three, so ask any provider for the level, not just the word 'aligned'.

Should we ask a technology provider about insurance?

Yes. Before you sign with any provider that will handle client data, ask which cover it holds, such as professional indemnity and cyber insurance, and for certificates of currency. It is a reasonable request and a quick way to check the cover matches the work. Ask us on the discovery call.

Can we see your security documents before we sign?

Ask for them on the free 45-minute discovery call or through our contact page. Tell us what your firm needs to see, such as answers to your own vendor security questionnaire or a list of sub-processors, and we will tell you what we can provide. If your firm uses its own vendor security questionnaire, send it before the call so the conversation can focus on the questions that matter most to your partners.

Secure by design. Set up correctly. Fully managed.

Talk to us before you commit to anything

Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.

Book a free 45-minute discovery call