Last updated 7 October 2026

Privacy policy

How MusterGRC collects, uses, protects and shares personal information, on this website and in our client work, and the choices you have.

1. About this policy

This policy covers personal information handled by MusterGRC through mustergrc.ai, through enquiries, and in delivering our services, including the Muster platform. Where a client agreement sets more specific terms for client data, that agreement applies alongside this policy.

We handle personal information under the Australian Privacy Act 1988 and the Australian Privacy Principles, and under the EU and UK General Data Protection Regulation (GDPR) where they apply to you. Privacy is managed as part of our information security management system, aligned with ISO/IEC 27001 (including control 5.34, privacy and protection of personal information), and our use of AI is governed under our AI management system, aligned with ISO/IEC 42001.

2. Who we are

OverWatchGRC Pty Ltd, trading as MusterGRC (“MusterGRC”, “we”), Sydney, Australia, is responsible for the personal information described here. Under the GDPR, we are the controller for website visitors, enquirers and our own business contacts. For personal information inside client material we work on, such as evidence and registers, our client is usually the controller and we act as their processor, under their instructions and our agreement with them.

Contact for anything in this policy: support@mustergrc.ai.

3. What we collect

We do not ask for sensitive information, such as health information. If it appears in client material, we handle it only as our client agreement allows and keep it to the minimum the work needs.

4. How and why we use it

We use personal information only for the purpose we collected it for, or a closely related purpose you would reasonably expect. For the GDPR, each use has a lawful basis:

We do not sell personal information, and we do not use it for direct marketing without your consent. You can opt out of any marketing at any time.

5. How we use AI

Our practitioners use AI tools to help draft documents, organise evidence and check work, and Vero AI provides independent verification of the work. In line with ISO/IEC 42001:

6. Who we share it with

We share personal information only with service providers who help us run the site and our services, under contracts that require them to protect it and use it only for that purpose:

We share client material with a certification body or auditor only when our client directs it, and we disclose information where the law requires it.

7. Where information is stored

Client information stays in Australia. Information from client engagements, including everything in the Muster platform and the material Vero AI verifies, is stored only in Australia. This is a fixed rule of how we work, not a setting.

The general business tools behind this website and our email (Cloudflare, Resend, Google Workspace and Apollo.io) may store or process website and enquiry information outside Australia, mainly in the United States. We choose providers with strong security commitments and contractual protections. For personal information covered by the GDPR, transfers outside the EU or UK rely on an adequacy decision or on the European Commission's Standard Contractual Clauses (or the UK equivalent).

8. How we protect it

We protect personal information with the controls of our information security management system, including:

If a data breach is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme and, where the GDPR applies, the relevant supervisory authority within 72 hours and affected people without undue delay.

9. How long we keep it

10. Cookies and tracking

The site sets no cookies of its own. Cloudflare's spam check sets one strictly necessary cookie, and the Apollo.io tracker keeps a visitor ID in your browser's local storage, but only for visitors outside the EU, the EEA, the UK and Switzerland. Our cookie policy lists each one, what it is for and how long it lasts, and how to block or clear them.

11. Your rights

You can ask us to:

Under the GDPR you also have the right to restrict or object to our use of your information, including any use based on our legitimate interests, to receive it in a portable format, and to withdraw consent at any time without affecting earlier use.

Email support@mustergrc.ai. We will confirm who you are and respond within 30 days, or within one month under the GDPR. There is no charge for a reasonable request. If your information is in client material we process for a client, we will pass your request to them and help them answer it.

12. Complaints

Please tell us first, at support@mustergrc.ai, and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992. If you are in the EU or UK, you can also complain to the data protection authority where you live or work.

13. Changes to this policy

We review this policy at least once a year as part of our management system review, and whenever how we handle personal information changes. The date at the top shows when it last changed.

Back to the home page