← Back to site

Privacy Policy

Version 1.0-2026-08  ·  August 2026

1Introduction

This document sets out the privacy policy of Chugh Technologies Pty Ltd (ACN 698 050 967), trading as Kritos Technology (referred to in this privacy policy as ‘we’, ‘us’, or ‘our’).
We take our privacy obligations seriously and we’ve created this privacy policy to explain how we store, maintain, use and disclose personal information.
We are committed to preventing serious invasions of privacy and ensuring the protection of your personal information, so you can contact us using the details below if you have any questions or concerns.
By providing personal information to us, you consent to our storage, maintenance, use and disclosing of personal information in accordance with this privacy policy.
We may change this privacy policy from time to time by posting an updated copy on our website and we encourage you to check our website regularly to ensure that you are aware of our most current privacy policy.

2About Kritos And This Policy

Kritos is an AI-assisted software platform that helps external auditors perform aspects of their audit work. Our customers (such as audit firms) upload their own engagement data — which may include their audit clients’ financial and personal information — and the platform processes it and returns draft workpapers for the auditor to review and finalise.
Where our customers input that engagement data into the platform, we handle it as a service provider on the customer’s behalf and on their instructions, under a separate data processing agreement. For that data, the customer (not Kritos) is responsible for it as the controlling entity, including for obtaining any necessary consents. This privacy policy explains how we handle personal information for which we are responsible — for example, information about our customers’ authorised users, website visitors, and people who contact us. If you are an individual whose information was uploaded to the platform by an audit firm, please contact that firm in the first instance.

3Types Of Personal Information We Collect

The personal information we collect may include the following:
(a)name;
(b)mailing or street address;
(c)email address;
(d)employer, job title and business contact details;
(e)telephone number and other contact details;
(f)login and account credentials, and authorised-user identifiers;
(g)technical and usage data, including IP address, device and browser information, and log and audit-trail records of your use of the platform;
(h)billing and payment information (for paid subscriptions);
(i)information about your business or personal circumstances;
(j)device and browser information and standard web log data;
(k)any other information provided by you to us via our website or our online presence, or otherwise required by us or provided by you.
We do not seek, and our platform is not intended to receive, sensitive information (such as health, biometric or genetic information) about website visitors or account users. Engagement data uploaded by customers is handled under the separate arrangements described above.

4How We Collect Personal Information

We may collect personal information either directly from you, or from third parties, including where you:
(a)contact us through our website;
(b)receive goods or services from us;
(c)submit any of our online sign up forms;
(d)communicate with us via email, telephone, SMS, social applications (such as LinkedIn or Facebook) or otherwise;
(e)interact with our website, social applications, services, content and advertising; and
(f)otherwise interact with us in connection with our services.
If you visit our website, we may use a small number of essential or functional cookies that are necessary for the website to operate (for example, to maintain your session or remember your preferences). We do not use Google Analytics or any third-party analytics, advertising or tracking technologies, and we do not track or profile your activity across other websites. You can disable cookies in your browser settings, although some parts of the website may not function properly if you do.

5Use Of Your Personal Information

We collect and use personal information for the following purposes:
(a)to provide goods, services or information to you;
(b)for record keeping and administrative purposes;
(c)to provide information about you to our contractors, employees, consultants, agents or other third parties for the purpose of providing goods or services to you;
(d)to improve and optimise our service offering and customer experience;
(e)to comply with our legal obligations, resolve disputes or enforce our agreements with third parties;
(f)to send you marketing and promotional messages and other information that may be of interest to you and for the purpose of direct marketing (in accordance with the Spam Act). In this regard, we may use email, SMS, social media or mail to send you direct marketing communications. You can opt out of receiving marketing materials from us by using the opt-out facility provided (e.g. an unsubscribe link);
(g)to send you administrative messages, reminders, notices, updates, security alerts, and other information requested by you; and
(h)to consider an application of employment from you.
We host and process personal information in Australia, using data centres located in Australia (Microsoft Azure, Australia East). We do not transfer, store or disclose personal information overseas without your consent, except where required by law. If we ever do disclose personal information to an overseas recipient, we will take such steps as are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles, as required by APP 8. We may engage trusted service providers (such as Microsoft Azure) to help us provide our services; where we do, they are bound to handle personal information consistently with this privacy policy and our obligations under the Privacy Act 1988 (Cth).

6Automated Decision-Making

We use automated and artificial-intelligence-based features to provide and improve our services (for example, to assist auditors by automating aspects of transaction testing). These features are subject to human oversight: outputs are presented for review and confirmation by a person before being relied on, and we do not use them to make decisions that produce legal or similarly significant effects on individuals. We do not use the engagement data that customers input into the platform to train, fine-tune or improve our models or services, and we do not share one customer’s data with any other customer. Where we improve the platform, we use only de-identified, aggregated or synthetic data that is no longer personal information. Our AI processing is performed within Microsoft Azure (Australia East). You can contact us about these features at ishwar@kritos.com.au.

7Security

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These measures include encryption of data in transit and at rest, access controls on a least-privilege basis, multi-factor authentication on privileged accounts, hosting in Australia, and documented incident-response procedures. We also comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth), and will notify the Office of the Australian Information Commissioner and affected individuals of any eligible data breach as required. However, no system is completely secure and we cannot guarantee the absolute security of your personal information.

8Data Retention

We keep personal information only for as long as we need it for the purposes described in this policy, or as required by law. Account and billing information is kept for the life of the account and a reasonable period afterwards. Engagement data uploaded by customers is retained and deleted in accordance with our agreement with the relevant customer; during evaluation or pilot use, engagement content is generally processed in real time and not retained beyond what is needed to deliver the output.

9Links

Our website may contain links to other websites. Those links are provided for convenience and may not remain current or be maintained. We are not responsible for the privacy practices of those linked websites and we suggest you review the privacy policies of those websites before using them.

10Requesting Access Or Correcting Your Personal Information

If you wish to request access to the personal information we hold about you, please contact us using the contact details set out below including your name and contact details. We may need to verify your identity before providing you with your personal information. In some cases, we may be unable to provide you with access to all your personal information and where this occurs, we will explain why. We will deal with all requests for access to personal information within a reasonable timeframe.
If you think that any personal information we hold about you is inaccurate, please contact us using the contact details set out below and we will take reasonable steps to ensure that it is corrected.

11Complaints

If you wish to complain about how we handle your personal information or believe your privacy has been seriously invaded, please contact us using the details provided below with your name and contact details. We will investigate your complaint promptly and respond within a reasonable timeframe.

12Contact Us

For further information about our privacy policy or practices, or to access or correct your personal information, or make a complaint, please contact us using the details set out below:
Name: Ishwar Chugh
Email: ishwar@kritos.com.au
Our privacy policy was last updated on 26 June 2026.