Privacy Policy
Effective 7 August 2026.
1. Who we are
Trail Guardian is a product of Witton Lane Pty Ltd (ABN to be inserted), an Australian Privacy Principles (APP) entity. References to "we", "us" or "our" mean Witton Lane Pty Ltd operating the Trail Guardian platform at trailguardian.com.au and related domains.
2. What personal information we collect
We collect (a) information you provide directly - name, work email, firm name, role, password, billing details; (b) information you upload - client records, policy data, file notes, PDS documents and audit material; (c) information generated by your use of the platform - log data, IP address, browser/device metadata, actions taken; and (d) information from our integration sources where you connect them (e.g. CRM imports). We do not knowingly collect information from anyone under 18.
3. Why we collect it
To provide the workspace, deliver compliance and audit features, authenticate users, process payments, send service notifications, support you, improve the product, prevent fraud or misuse, and comply with our legal obligations including the Corporations Act and Anti-Money Laundering and Counter-Terrorism Financing Act.
4. Where your data is stored
All customer data is stored in Australia (AWS Asia Pacific - Sydney, ap-southeast-2). Backups also remain in Australia. See our Security & Data Residency page for the full technical detail. We do not transfer personal information overseas for storage. Limited service providers (e.g. Stripe for payments, our email infrastructure) may process metadata outside Australia under contractual safeguards; we will list these on request.
5. How we share information
We do not sell personal information. We share information only with: (a) service providers acting on our instructions under written contracts; (b) your own firm's authorised users; (c) regulators, law enforcement or courts where compelled by law; and (d) a successor entity in the event of a sale or merger, subject to equivalent obligations.
6. Use of data for AI / model training
We will never use your client data, audit material or uploaded documents to train third-party AI models, nor to train models that benefit other customers. Any AI features inside the platform operate on your firm's data within your firm's workspace only.
7. Retention
Active customer data is retained for the life of your subscription plus 90 days. Audit trail and AFCA defence material is retained for a minimum of 7 years to meet Corporations Act record-keeping obligations, then archived to immutable cold storage in Australia. You can request earlier deletion of non-statutory data at any time.
8. Your rights
Under the Australian Privacy Principles you may: request access to the personal information we hold about you; request correction of inaccurate information; withdraw consent for non-essential processing; export your data; and lodge a complaint with us or the Office of the Australian Information Commissioner (oaic.gov.au).
9. Security
We use TLS 1.3 in transit, AES-256 at rest, scoped IAM, row-level access control, S3 Object Lock for audit material, and continuous monitoring. Despite reasonable safeguards, no system is perfectly secure. If a Notifiable Data Breach occurs we will notify affected firms within 24 hours of confirmation, well inside the 30-day statutory window.
10. Cookies & analytics
We use strictly-necessary cookies for authentication and session management. We do not run advertising trackers. We use privacy-respecting product analytics (aggregated, no client PII) to improve the platform. You can disable non-essential cookies in your browser without losing access to the platform.
11. Children
Trail Guardian is a B2B product for licensed Australian financial services firms and is not directed at individuals under 18.
12. Changes to this policy
We will post material changes on this page with a revised effective date. Where changes are significant we will notify account administrators by email at least 14 days before they take effect.
13. Contact us
For any privacy question, request or complaint, email toby@wittonlane.com. We will acknowledge within 5 business days and respond substantively within 30 days. If you are unsatisfied with our response you may contact the Office of the Australian Information Commissioner.
