Trust
The answers your procurement, security and audit teams are going to ask for.
One page, one posture, across every Themis Systems product. If something here is not enough detail for your assessment, ask and we will send the underlying document under NDA.
Certifications and frameworks
Independently assessed, not self-declared
ISO 27001
Information security management system covering the platform, the development lifecycle and the people who operate it.
ISO 42001
AI management system governing how models are selected, evaluated, monitored and retired, including the image analysis used in audit workflows.
SOC 2
Service organisation controls reporting for security, availability and confidentiality, available to customers and prospects under NDA.
Certificate scope, issue dates and certification body details are provided with the security pack. We do not claim coverage beyond the certified scope.
Hosting and data residency
Australian-hosted, with the boundary written down
Customer data is hosted in Australian regions. Where a sub-processor operates outside Australia, it is named, its purpose is stated, and the transfer basis is documented. That happens before you sign, not after an incident.
- Primary hosting
- Australian cloud regions, with backups retained in-country.
- Encryption
- In transit and at rest, with documented key management.
- Access control
- Role-based access, least privilege, multi-factor authentication and reviewed administrative access.
- Logging
- Immutable audit history on compliance records; platform and security event logging retained per policy.
- Resilience
- Documented backup, restore, business continuity and disaster recovery plans, tested on a defined cycle.
- Sub-processors
- Maintained list with purpose and location, provided on request and updated with notice.
Responsible AI
AI narrows the human's search. It does not sign the certificate.
Our image analysis and assistive features exist to direct attention: flagging missing, duplicated or inconsistent evidence so a qualified reviewer spends their time on judgement. A model does not approve a job, create a certificate or set a condition score on its own.
Every automated flag records the model version and the input it acted on, so an auditor can reconstruct why a job was escalated. Customer data is not used to train third-party foundation models.
Privacy and contracting
Australian privacy law is the baseline
- Privacy Act 1988 (Cth)
- We handle personal information consistently with the Australian Privacy Principles. Installer and resident personal information is collected for a stated purpose and retained only as long as the scheme or contract requires.
- Data processing agreements
- Standard DPA available, covering purpose limitation, sub-processing, breach notification timeframes and deletion on termination.
- Notifiable data breaches
- Documented assessment and notification process aligned to the NDB scheme, with customer notification obligations stated in contract.
- Data return and deletion
- Structured export in machine-readable format on request, and certified deletion at end of contract.
- Insurance
- Professional indemnity, public liability and cyber cover held; certificates of currency provided on request.
Note for reviewers. This page states our posture in summary form. The evidence behind each line (certificates, policies, penetration test summaries, the sub-processor register and the DPA) is provided in the security pack on request.
Privacy Policy
Themis Systems Privacy Policy
This Privacy Policy applies to all personal information collected by Themis Systems Pty Ltd (we, us or our) via the website located at themis-systems.com.au, the portals located at tammy.themis-app.com.au and Install.themis-app.com.au, the associated mobile applications Tammy and Themis Install, together our Properties (Properties).
1. What information do we collect?
The kind of Personal Information that we collect from you will depend on how you use the Properties. The Personal Information which we collect and hold about you may include: name, address, phone number, email address, payment details, login credentials, trade licences and certifications, GPS location, photographs, and technical or usage information such as device and browser details and diagnostic or error reports.
Some of this information is provided by you directly, and some is collected through the service providers we use to operate the Properties. For example, our identity provider facilitates your login and provides your name and email address to us, our payment processor collects your payment details on our behalf, and our analytics and error-monitoring tools collect technical and usage information as described in clause 4 below.
2. Types of information
The Privacy Act 1988 (Cth) (Privacy Act) defines types of information, including Personal Information and Sensitive Information.
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable:
- whether the information or opinion is true or not; and
- whether the information or opinion is recorded in a material form or not.
If the information does not disclose your identity or enable your identity to be ascertained, it will in most cases not be classified as “Personal Information” and will not be subject to this privacy policy.
Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
Sensitive Information will be used by us only:
- for the primary purpose for which it was obtained;
- for a secondary purpose that is directly related to the primary purpose; and
- with your consent or where required or authorised by law.
3. How we collect your Personal Information
- We may collect Personal Information from you whenever you input such information into the Properties or provide it to us in any other way.
- We also use cookies and similar tracking technologies, together with analytics and error-monitoring tools, which enable us to tell when you use the Properties, understand how the Properties are being used, and diagnose and fix technical issues.
- These technologies are retained for up to 30 days and can be managed through your browser settings.
- Generally, it is not possible to identify you personally from our use of these technologies, however where you are signed in, they may be linked to your account.
- We generally don't collect Sensitive Information, but when we do, we will comply with the preceding paragraph.
- Where reasonable and practicable we collect your Personal Information from you only. However, sometimes we may be given information from a third party, in which case we will take steps to make you aware of the information that was provided by a third party.
4. Purpose of collection
- We collect Personal Information to provide you with the best service experience possible in the Properties and keep in touch with you about developments in our business.
- We use your Personal Information to respond to enquiries made through the Properties, provide account and service-related communications, and share product updates and release notes relevant to the Properties you use. These are operational communications tied to your use of the Properties, not direct marketing.
- If we ever wish to send you direct marketing (for example, a newsletter or promotional content unrelated to your account), we will only do so with your consent, and every such message will include a clear way to opt out.
- We do not use third-party advertising or marketing cookies, and we do not allow any advertising network to place tracking cookies in the Properties for cross-site or targeted advertising purposes. We do not sell or share your Personal Information with advertising or data-broker networks. The only cookies and similar technologies we use are first-party analytics and error-monitoring tools (PostHog and Sentry), used solely to understand how the Properties are used and to diagnose and fix technical issues, never to build an advertising profile of you.
5. Security, Access and correction
- We store your Personal Information in a way that reasonably protects it from unauthorised access, misuse, modification or disclosure, including through encryption and access controls. When we no longer require your Personal Information for the purpose for which we obtained it, we will take reasonable steps to destroy, anonymise or de-identify it. Most of the Personal Information that is stored in our client files and records will be kept for a maximum of 7 years to fulfil our record-keeping obligations.
- The Australian Privacy Principles:
- permit you to obtain access to the Personal Information we hold about you in certain circumstances (Australian Privacy Principle 12); and
- allow you to correct inaccurate Personal Information subject to certain exceptions (Australian Privacy Principle 13).
- Where you would like to obtain such access, please contact us in writing on the contact details set out at the bottom of this privacy policy.
6. Complaint procedure
If you have a complaint concerning the manner in which we maintain the privacy of your Personal Information, please contact us as on the contact details set out at the bottom of this policy. All complaints will be considered by the Privacy Officer, and we may seek further information from you to clarify your concerns. If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the problem. If you remain dissatisfied with the outcome, you may refer the matter to the Office of the Australian Information Commissioner.
7. Documentation and Response Timeline
We will acknowledge receipt of your complaint within 3 business days and provide you with a reference number. Our Privacy Officer will investigate your complaint and maintain detailed records of all communications and findings. We aim to resolve all privacy complaints within 10 business days. If additional time is required, we will notify you in writing. All complaint documentation will be retained for 12 months following resolution.
8. Overseas transfer
Some Personal Information may be disclosed to overseas recipients as part of how we operate the Properties.
Our error-monitoring provider, Sentry, processes error reports (including your account identifier, name and email address where applicable) in the European Union.
Our analytics and session-recording provider, PostHog, is also hosted in the European Union. We route this traffic through infrastructure we control, but the underlying data is still received and processed on PostHog's servers. To limit what leaves Australia through this channel, session recordings are configured to mask all text and images before they are captured, so information visible on screen during a session (such as photographs) is not included in what is sent overseas. Certain other data sent to PostHog also has automatic, pattern-based redaction applied on receipt, to remove common identifiers such as email addresses and authentication tokens; PostHog describes this as best-effort and it does not catch every possible identifier.
We take reasonable steps to ensure our overseas recipients handle your information consistently with the Australian Privacy Principles, including through contractual data processing terms. A current list of overseas recipients and the basis for each transfer is available on request or in our Trust documentation.
9. Themis as a 3rd Party Processor
If you're a customer of a business that uses our Properties (for example, an energy saver whose installation was managed through Themis Install), your personal information is collected and disclosed by that business in accordance with its own privacy arrangements. We process it on their behalf, as their software provider, under contract.
10. How to contact us about privacy
If you have any queries, or if you seek access to your Personal Information, or if you have a complaint about our privacy practices, you can contact us through: privacy@themis-systems.com.au.
Security pack
Send us your questionnaire.
We would rather complete your standard assessment than ask you to accept ours. Send the questionnaire and we will return it with evidence attached.