Last updated 7 October 2026
Privacy policy
How MusterGRC collects, uses, protects and shares personal information, on this website and in our client work, and the choices you have.
1. About this policy
This policy covers personal information handled by MusterGRC through mustergrc.ai, through enquiries, and in delivering our services, including the Muster platform. Where a client agreement sets more specific terms for client data, that agreement applies alongside this policy.
We handle personal information under the Australian Privacy Act 1988 and the Australian Privacy Principles, and under the EU and UK General Data Protection Regulation (GDPR) where they apply to you. Privacy is managed as part of our information security management system, aligned with ISO/IEC 27001 (including control 5.34, privacy and protection of personal information), and our use of AI is governed under our AI management system, aligned with ISO/IEC 42001.
2. Who we are
OverWatchGRC Pty Ltd, trading as MusterGRC (“MusterGRC”, “we”), Sydney, Australia, is responsible for the personal information described here. Under the GDPR, we are the controller for website visitors, enquirers and our own business contacts. For personal information inside client material we work on, such as evidence and registers, our client is usually the controller and we act as their processor, under their instructions and our agreement with them.
Contact for anything in this policy: support@mustergrc.ai.
3. What we collect
- If you contact us: your name, work email, company if you give it, and your message.
- When you visit the site: standard request information, such as IP address, browser and pages viewed, and, through the Apollo.io tracker, the organisation a visit appears to come from. The Apollo tracker does not run for visitors in the EU, the EEA, the UK or Switzerland.
- Clients and their people: business contact details of client staff, and personal information contained in the material we review or build with you, such as names and roles in registers, policies, access reviews and audit evidence.
- Suppliers and partners: business contact and billing details.
We do not ask for sensitive information, such as health information. If it appears in client material, we handle it only as our client agreement allows and keep it to the minimum the work needs.
4. How and why we use it
We use personal information only for the purpose we collected it for, or a closely related purpose you would reasonably expect. For the GDPR, each use has a lawful basis:
- Replying to enquiries and talking with you about our services: our legitimate interest in responding to you, or steps you ask us to take before a contract.
- Delivering our services and running the Muster platform: performance of our contract with our client, or our client's instructions where we are their processor.
- Understanding which organisations visit the site (outside the EU, EEA, UK and Switzerland only): our legitimate interest in understanding interest in our work.
- Keeping the site and our systems secure, including spam checks: our legitimate interest in protecting our services.
- Invoicing, record keeping and legal obligations: legal obligation.
We do not sell personal information, and we do not use it for direct marketing without your consent. You can opt out of any marketing at any time.
5. How we use AI
Our practitioners use AI tools to help draft documents, organise evidence and check work, and Vero AI provides independent verification of the work. In line with ISO/IEC 42001:
- A qualified person reviews AI output before it is relied on. AI does not make decisions about you that have legal or similarly significant effects, and we do not carry out automated decision-making of that kind.
- We assess AI providers before use, including how they handle and protect data, and we use them under terms that do not allow your information to be used to train their models.
- We put only the information a task needs into an AI tool.
6. Who we share it with
We share personal information only with service providers who help us run the site and our services, under contracts that require them to protect it and use it only for that purpose:
- Cloudflare: website hosting, security, spam checks (Turnstile) and cookie-free visit statistics.
- Resend: delivering contact form messages to our mailbox.
- Google Workspace: our email and documents.
- Apollo.io: identifying the organisations that visit the site, for visitors outside the EU, EEA, UK and Switzerland.
- Vero AI and our AI model providers: independent verification and AI assistance, as described in section 5, with client information stored only in Australia.
We share client material with a certification body or auditor only when our client directs it, and we disclose information where the law requires it.
7. Where information is stored
Client information stays in Australia. Information from client engagements, including everything in the Muster platform and the material Vero AI verifies, is stored only in Australia. This is a fixed rule of how we work, not a setting.
The general business tools behind this website and our email (Cloudflare, Resend, Google Workspace and Apollo.io) may store or process website and enquiry information outside Australia, mainly in the United States. We choose providers with strong security commitments and contractual protections. For personal information covered by the GDPR, transfers outside the EU or UK rely on an adequacy decision or on the European Commission's Standard Contractual Clauses (or the UK equivalent).
8. How we protect it
We protect personal information with the controls of our information security management system, including:
- access limited to the people who need it, with multi-factor authentication;
- encryption in transit;
- security assessment of suppliers before we use them;
- confidentiality obligations for everyone who works with us;
- logging and monitoring, and a tested incident response process.
If a data breach is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme and, where the GDPR applies, the relevant supervisory authority within 72 hours and affected people without undue delay.
9. How long we keep it
- Enquiries: for as long as the conversation is active, then deleted within two years of our last contact, unless you become a client.
- Client engagements: for the engagement and as our client agreement sets, then returned or securely deleted.
- Financial and business records: seven years, as Australian tax law requires.
10. Cookies and tracking
The site sets no cookies of its own. Cloudflare's spam check sets one strictly necessary cookie, and the Apollo.io tracker keeps a visitor ID in your browser's local storage, but only for visitors outside the EU, the EEA, the UK and Switzerland. Our cookie policy lists each one, what it is for and how long it lasts, and how to block or clear them.
11. Your rights
You can ask us to:
- tell you what personal information we hold about you and give you a copy;
- correct information that is wrong or out of date;
- delete it, where we no longer need it or have no lawful basis to keep it.
Under the GDPR you also have the right to restrict or object to our use of your information, including any use based on our legitimate interests, to receive it in a portable format, and to withdraw consent at any time without affecting earlier use.
Email support@mustergrc.ai. We will confirm who you are and respond within 30 days, or within one month under the GDPR. There is no charge for a reasonable request. If your information is in client material we process for a client, we will pass your request to them and help them answer it.
12. Complaints
Please tell us first, at support@mustergrc.ai, and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992. If you are in the EU or UK, you can also complain to the data protection authority where you live or work.
13. Changes to this policy
We review this policy at least once a year as part of our management system review, and whenever how we handle personal information changes. The date at the top shows when it last changed.