Varðaᚹ
Launch App →

Privacy Policy

Last updated: 5 July 2026

Placeholder notice: Varða is operated as a sole trader with a registered ABN and business name. Wherever this policy still says "[Business Name]," that is a placeholder pending the registered name being added to this page: everything else on this page reflects how the product actually handles data today.

This policy explains what information Varða ("we," "us," "our product") collects when you use the Varða compliance-assessment tool, how it's used, who it's shared with, and how it's stored.

1. What we collect

When you use Varða, you may provide:

  • Your organisation's name and the compliance framework you select (e.g. ISO 27001, CPS 234)
  • Policy documents you upload (PDF or Word), or text you paste directly, for assessment
  • Evidence you record against individual controls: stakeholder names, notes, additional context, and any evidence files you attach
  • A reviewer name and a notification email address, if you choose to provide them (used only to personalise reports and to send you a staleness alert if a review is left inactive)

We do not require you to create an account, and we do not collect payment details, government identifiers, or any information beyond what you choose to type or upload into the tool.

2. How we use it

Everything you provide is used for one purpose: to generate your compliance gap assessment, evidence request list, and control effectiveness testing output. Your uploaded documents and evidence text are sent to Anthropic's Claude API (see below) so that our AI models can analyse them against the framework you selected. We do not use your data to train any AI model, and we do not sell or share it with advertisers.

3. Who we share it with

Varða is built on a small number of infrastructure providers, each of whom processes data strictly to make the product work:

  • Anthropic: the text of your uploaded policy documents and evidence is sent to Anthropic's Claude API to generate gap assessments, executive summaries, evidence requests, and effectiveness ratings. See Anthropic's privacy policy for how they handle API data, and their Data Processing Addendum for the contractual terms governing that processing. Anthropic's standard commercial terms confirm this data is not used to train their models without our express permission.
  • Microsoft Azure: the application and its database are hosted on Microsoft Azure infrastructure in Australia (Australia East region). Azure Communication Services (Microsoft's own service, via its default Azure-managed email domain, not a separate third-party email vendor) is used to send you staleness alert emails, if you've provided a notification address.

We do not use any analytics, advertising, or tracking services on this site.

4. How we store it and how long we keep it

Your review is stored in a database on our Azure-hosted server, protected behind a password gate. Varða is currently built as a single-review tool: starting a new assessment overwrites the previous one, and there is no automatic deletion schedule beyond that. If you'd like your data deleted sooner, contact us (below) and we'll remove it directly.

Uploaded files themselves are not stored; only the text extracted from them is kept, for efficiency. The original file is discarded once its text has been read.

5. Cookies

Varða does not currently use cookies, analytics, or any tracking technology. The only thing that identifies you to the site is the shared access password.

6. Your rights

You can ask us to access, correct, or delete any information you've submitted at any time. Since there's no account system, just contact us directly (below) and we'll act on it promptly.

7. Changes to this policy

If how we handle data changes materially, we'll update this page and change the "last updated" date above.

8. Contact

Questions about this policy can be sent to Varda.AU@outlook.com, operated by [Business Name] (ABN: 57 762 521 645).

© 2026 Varða. Home · About · FAQ · Privacy Policy · Terms of Service · Pricing